Splunk Search

SPL on configuration files

jadengoho
Builder

Hi , 

I would like to know if we can use SPL commands on configuration files to filter incoming data ?

Cause using Regex is out of option.

 

Labels (1)
Tags (1)
0 Karma
1 Solution

jadengoho
Builder

This is eval, could i really use to filter the events before index time without using regex?

0 Karma

jadengoho
Builder

This works 🙂
Using eval to input a index time field and identify which will be ingested or not.

jadengoho_0-1613355664770.png

 

.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!