Hello Experts,
The CSV file is located on file share and file is having columns
Hostname, type, IP.
From these three columns I would like to ingest Hostname and IP columns and ignore Type column. I want to do this to save disk space on splunk indexers.
Please suggest.
Thank you.
Hi @email2vamsi,
You can use INGEST_EVAL on indexers to remove unwanted columns;
props.conf
[your_sourcetype]
INDEXED_EXTRACTIONS = CSV
TRANSFORMS-drop_fields = drop_useless_fields
EXTRACT-removed_columns = [^,]+,(?<type>[^,]+)
transforms.conf
[drop_useless_fields]
INGEST_EVAL = type:=null()