Getting Data In

Need to prevent pattern from being parsed and shown in to the logs.

saxenaamit
New Member

I am trying to parse this message and sending "Timer_ConnectionIdle" in to nullQueue. I am not using heavy forwarders so that I can't use props.conf and transforms.conf files in the app deployment folder ( where we have inputs.conf file for the related index). I am trying to change/ create files ( props.conf or transforms.conf) in SPLUNK_HOME/etc/system/local as suggested in articles to use indexers if there is a light forwarder.

2016-08-09 14:26:23 10.30.70.180 54809 10.30.15.216 80 - - - - - Timer_ConnectionIdle -
2016-08-09 14:23:28 10.30.60.203 57988 10.30.15.241 80 HTTP/1.1 GET /Ops/Main.asp?Bus_Unit=800024&busUnit=800024&country_id=US&RegionCode=&TabSelect=7&WhichTab=&type=summary - 27 Client_Reset sitedataasp.uat.crowncastle.com+AppPool

I am not getting this working even though I tried changing the location of props.conf and transforms.conf as well as configuration.

Transforms.conf
[null_filter]
REGEX=Timer_ConnectionIdle
DEST_KEY=queue
FORMAT=nullQueue

props.conf
[source::C:\Windows\System32\LogFiles\HTTPERR\httperr54.log]
TRANSFORMS-null=null_filter

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Put the props and transforms on the universal forwarder AND the indexers.

0 Karma

sundareshr
Legend

Try this, restart splunk

Transforms.conf
[null_filter]
REGEX=Timer_ConnectionIdle
DEST_KEY=queue
FORMAT=nullQueue

props.conf
[source::C:\\Windows\\System32\\LogFiles\\HTTPERR\\httperr54.log]
TRANSFORMS-null=null_filter
0 Karma

saxenaamit
New Member

Thanks Sunder. I have already tried it before and didn't get it working.

0 Karma

sundareshr
Legend

Did you try escaping the \ And is this on the indexer? Then I would suggest try using sourcetype stanze. Maybe something with the source stanza

0 Karma

saxenaamit
New Member

Did you try escaping the `` - I didn't get about what you are indicating.
And is this on the indexer- Yes, we are not using heavy forwarders so, I found that we need to use indexers to get this working.
Then I would suggest try using sourcetype stanze. Maybe something with the source stanza- I have tried with sourceType instead of using source. SourceType value what I used came from inputs.conf. I did't get it working.

Can you list steps to configure by which we can send data to nullQueue without using heavy forwarders? It seems I might be missing a step.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...