Splunk Search

index only a part of a logfile

jonthanze
Explorer

is there a way in Splunk to index only the event of a log files that contains a specific expression or doesn't contains it.
By example, if I index a very big logfile, i don't want to index in it the INFO event but only the ERROR events.

thanks

Tags (3)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi jonthanze,

yes, there is a way to do this in Splunk. You can filter events according to their content and route it to different Splunk Queues or indexes or 3rd Party Systems.
Docs is your friend, please see this

hope this helps to get you started ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...