All Apps and Add-ons

How to ignore a log event from indexing?

kiran331
Builder

Hi

We have firewall logs coming in through syslog/Heavy Forwarder, I have a log event which contains below message taking up lot of space. How to ignore this while indexing?

Apr 3 09:59:00 123.22.132.4 :Apr 03 15:04:00 UTC: %ASA-session-1-106021: Deny UDP reverse path check from 122.23.24.25 to 11.12.13.14 on interface inside

excluding the events which contains "Deny UDP reverse path check from 122.23.24.25 to 11.12.13.14 on interface inside"

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

You can route events to the nullqueue. Here is the relevant doc:

http://docs.splunk.com/Documentation/Splunk/6.5.3/Forwarding/Routeandfilterdatad#Filter_event_data_a...

Jacob
Sr. Technical Support Engineer
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...