Hi Experts,
I am getting data from 10 sources, I want to send 3 source data to nullque.
I tried with below props.conf and transforms.conf configuration. But first source is filtering events from reset is not working.
vi props.conf
[source::ghcmapp]
[source::lsof]
[source::ps]
TRANSFORMS-null = setnull
vi transforms.conf
[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
Tried with individual stanza for each source, but its not working.
You original config entries might be different but just to confirm, did you add TRANSFORMS-null=setnull under each of the source stanza? If not add the entry to each of the source stanza you want to filter- in this case ghcmapp,lsof,ps
You can set its based on sourcetype spec also , for eg:
[ps]
TRANSFORMS-null = setnull