Getting Data In

Ignoring a specific portion of the log file (header/footer)


I want splunk to start indexing my log file only after it encountered a specific string/regex.

Everything before that marker should be ignored as I have no use for it.

Is there any way to do that?


Splunk Employee
Splunk Employee

For Splunk 6, see:

Specifically the example on ignoring useless long headers.

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!