Splunk Search

index only a part of a logfile

jonthanze
Explorer

is there a way in Splunk to index only the event of a log files that contains a specific expression or doesn't contains it.
By example, if I index a very big logfile, i don't want to index in it the INFO event but only the ERROR events.

thanks

Tags (3)
0 Karma

MuS
Legend

Hi jonthanze,

yes, there is a way to do this in Splunk. You can filter events according to their content and route it to different Splunk Queues or indexes or 3rd Party Systems.
Docs is your friend, please see this

hope this helps to get you started ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...