Getting Data In

Is it possible to filter events after indexing, but before they are forwarded?

jambajuice
Communicator

I'm gathering the _internal index from several hundred remote hosts, but the only events I want to collect centrally are warnings and errors. Is it possible to filter what events get forwarded to the central indexer?

Thx.

Craig

Tags (1)
0 Karma

woodcock
Esteemed Legend

The _internal index is not really "yours" to mess with and I highly advise against even trying. Doing so will surely cause some apps not to work correctly (e.g. SoS, etc.), might cause Splunk support to be hampered in assisting you, and could even (conceivably) break your support agreement. It does not impact your license and shouldn't be too much disk space so why not just leave well enough alone?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...