Getting Data In

Ignoring a specific portion of the log file (header/footer)

KidCrippler
Engager

I want splunk to start indexing my log file only after it encountered a specific string/regex.

Everything before that marker should be ignored as I have no use for it.

Is there any way to do that?

Thanks

ogdin
Splunk Employee
Splunk Employee

For Splunk 6, see:

http://docs.splunk.com/Documentation/Splunk/latest/Data/Extractfieldsfromfileheadersatindextime

Specifically the example on ignoring useless long headers.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...