Splunk Search

SPL on configuration files

jadengoho
Builder

Hi , 

I would like to know if we can use SPL commands on configuration files to filter incoming data ?

Cause using Regex is out of option.

 

Labels (1)
Tags (1)
0 Karma
1 Solution

jadengoho
Builder

This is eval, could i really use to filter the events before index time without using regex?

0 Karma

jadengoho
Builder

This works 🙂
Using eval to input a index time field and identify which will be ingested or not.

jadengoho_0-1613355664770.png

 

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...