Hi,
Is there a way to ignore a event containing the message before indexing using regex in props.conf and transforms.conf
ignore the msg contains "10.11.12.133 to 10.11.12.134 "?
You can follow instructions from below link on dropping specific events ( containing those IP addresses) and index the rest.
On INdexer/Heavy Forwarder (whichever comes first in flow)
In props.conf, set the TRANSFORMS-null attribute:
[
[YourSourceTypeNameHere]
TRANSFORMS-null= setnull
Create a corresponding stanza in transforms.conf. Set DEST_KEY to "queue" and FORMAT to "nullQueue":
[setnull]
REGEX = (10\.11\.12\.133|10\.11\.12\.134)
DEST_KEY = queue
FORMAT = nullQueue
Restart Splunk Enterprise.
When you say "ignore" do you mean "prevent from being indexed" or "once indexed, prevent from showing in my search"?
Assuming the former:
You can follow instructions from below link on dropping specific events ( containing those IP addresses) and index the rest.
On INdexer/Heavy Forwarder (whichever comes first in flow)
In props.conf, set the TRANSFORMS-null attribute:
[
[YourSourceTypeNameHere]
TRANSFORMS-null= setnull
Create a corresponding stanza in transforms.conf. Set DEST_KEY to "queue" and FORMAT to "nullQueue":
[setnull]
REGEX = (10\.11\.12\.133|10\.11\.12\.134)
DEST_KEY = queue
FORMAT = nullQueue
Restart Splunk Enterprise.
Hi,
I also have 2 more IP's to avoid before Indexing, 169.225.1.2.3 and 165.244.253.255, Do I have to create new stanza Or I can use the old one to add Ip's?
just add them to the existing stanza like this
(10\.11\.12\.133|10\.11\.12\.134|<next-ip>|<next-ip>)
Thank you
Hi somesoni2,
I added this on Heavy Forwarder and also On indexers, I changed it to ignore any logs containing 169.244.255.255. I still see the logs indexing,
I added the below in props.conf and transforms.conf.
props.conf
[cisco:asa]
TRANSFORMS-null= setnull
[setnull]
REGEX = (169.254.255.255)
DEST_KEY = queue
FORMAT = nullQueue
Hi,
maybe try to "escape" the dots in your regex.
Like this: (169\.254\.255\.255)
Hi,
I'm using . , It was changed in the comment.
Did you restart Splunk after making the change? ALso, this filter will be applicable for any data that'll come after you made the change, any older data would remain as is.
Thank you it worked.