Splunk Search

index only a part of a logfile

jonthanze
Explorer

is there a way in Splunk to index only the event of a log files that contains a specific expression or doesn't contains it.
By example, if I index a very big logfile, i don't want to index in it the INFO event but only the ERROR events.

thanks

Tags (3)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi jonthanze,

yes, there is a way to do this in Splunk. You can filter events according to their content and route it to different Splunk Queues or indexes or 3rd Party Systems.
Docs is your friend, please see this

hope this helps to get you started ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...