EVENT_SESH;0;01/03/2018 22:57:27:5000;1;1;0;;;END OF IMPORT PROCESS FOR THE MASTER STORE - PENDING_TXT(0)
after this line I want to ignore all the lines before indexing from the log files. Please suggest me how can i do this with the help of sedcmd command. I am using universal forwarder.
Please also tell me the exact path where I have to make changes for props.conf. I'm using windows OS
This answer might help you.
https://answers.splunk.com/answers/594894/blacklist-log-events-not-log-filenames-using-a-str.html
This basically black-holes data that meets a specific regex. Of course, if the lines are not uniform this will be difficult.
http://docs.splunk.com/Documentation/Splunk/7.0.2/Forwarding/Routeandfilterdatad
forgot to mention my source name (source: D:\CentralData\MONACO)