Splunk Search

SPL on configuration files

jadengoho
Builder

Hi , 

I would like to know if we can use SPL commands on configuration files to filter incoming data ?

Cause using Regex is out of option.

 

Labels (1)
Tags (1)
0 Karma
1 Solution

jadengoho
Builder

This is eval, could i really use to filter the events before index time without using regex?

0 Karma

jadengoho
Builder

This works 🙂
Using eval to input a index time field and identify which will be ingested or not.

jadengoho_0-1613355664770.png

 

Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...