I wish to run a python script that updates files within a monitoring directory, without directly sending any files to the index. All the examples I’ve seen have people running a script and sending logs to their index.
Would removing the sourcetype/ index fields make it act the way I want? Or will it behave the way I want as long as I’m not sending logs within the script. Sorry for any confusion.
1 2 3 4 5 | [script://./bin/TA-SimpleApp.py] interval = 10 sourcetype = my_sourcetype disabled = False index = main |
You could drop all data from your custom sourcetype into the nullQueue so that it doesnt reach the indexing queue. The below should help:
props.conf
[my_sourcetype]
TRANSFORMS-ignore = null_queue
transforms.conf
[nullqueue]
REGEX = .
DEST = queue
FORMAT = nullQueue