Hello All,
I am working on props.conf and transforms.conf files to clean some data before indexing the data into splunk so i have some data like
I want to exclude these lines while indexing data into Splunk. i know we can use blacklist and whitelist to exclude the files in inputs.conf file
Can anyone help me out here.
Thanks
Another option is the nullQueue filtering, but has more cost at indextime to parse all the events.
Hello Yannk,
nullQueue is not able to remove # lines from file here is the prop
9/17/01 1:02:50.000 AM
Example:
It taking this whole thing as one event
Thanks
Gajanan Hiroji
Are you trying to ignore the preamble of a log file? If so, give PREAMBLE_REGEX
in props.conf a shot. See http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Extractfieldsfromfileheadersatindextime#Props... for documentation.
That should do it.
Hello Martin,
will this work to remove lines from file which are starts with #?
PREAMBLE_REGEX=^#
Thanks
Gajanan HIroji