Splunk Search

SPL on configuration files

jadengoho
Builder

Hi , 

I would like to know if we can use SPL commands on configuration files to filter incoming data ?

Cause using Regex is out of option.

 

Labels (1)
Tags (1)
0 Karma
1 Solution

jadengoho
Builder

This is eval, could i really use to filter the events before index time without using regex?

0 Karma

jadengoho
Builder

This works 🙂
Using eval to input a index time field and identify which will be ingested or not.

jadengoho_0-1613355664770.png

 

Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...