Hello All!
I am trying to discard a certain event before the Indexers Ingest it using keyword envoy. Below is an example
timestamp vcenter envoy-access 2024-12-29T23:53:56.632Z info envoy[139855859431232] [Originator@6876 sub=Default] 2024-12-29T23:53:50.392Z POST /sdk HTTP/1.1 200 via_upstream
I tried creating props and transforms conf in $SPLUNK_HOME/etc/system/local but it's not working. My questions are if my stanzas are correct and if I should put them in local directory? Appreciate any assistance you can provide, Thank you.
Props.conf
[nullQueue]
queue = nullQueue
[host::vcenter]
TRANSFORMS-null = setnull
[source::/var/log/remote/catchall/(IPAddress of Vcenter)/*.log]
TRANSFORMS-null = setnull
transforms.conf
[setnull]
REGEX = envoy
DEST_KEY = queue
FORMAT = nullQueue
... View more