The eStreamer input generates like 300 MB of log files per day. Is there any way to disable that logging?
Hi responsys_cm,
to disable eStreamer input, you have to disable Splunk inputs for this App, there are two ways:
If you receive also logs using syslog, remember to disable this in your CISCO interface.
Bye.
Giuseppe
My goal isn't to disable the input. The input generates log files on its operations as well as indexing data from FireSIGHT. I want the FireSIGHT data, but not the hundreds of megs of the inputs operational logs...
you have to chose the logs you want to discard, find the correct regex and then filter your data using the regex:
(http://docs.splunk.com/Documentation/Splunk/6.5.1/Forwarding/Routeandfilterdatad)
props.conf
[your_sourcetype]
TRANSFORMS-null= setnull
transforms.conf
[setnull]
REGEX = your_regex
DEST_KEY = queue
FORMAT = nullQueue
and restart Splunk
bye.
Giuseppe
These logs aren't being ingested by Splunk. They are logs that the eStreamer script generates. They consume hundreds of megs a day.
Sorry, I don't know eStreamer and i don't know how to disable log!
Bye.
Giuseppe