Getting Data In

Can I filter logs coming from forwarders with config files under \etc\system or logs can be filtered just from heavy forwarders?

CsungyiPepi19
New Member

Can I filter logs coming from forwarders with config files under \etc\system or logs can be filtered just from heavy forwarders? I installed splunk forwarders and wanted to filter logs so I have tried to create props.conf and transforms.conf under \etc\System\local but there was no effect. When I install heavy forwarders it worked deploying config files (under \etc\deploymentapps).

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi CsungyiPepi19,
logs can be filtered only on Indexers and (when present) on Heavy Forwarders as you can see at https://docs.splunk.com/Documentation/Splunk/7.3.2/Forwarding/Routeandfilterdatad.
There's only one filter that can be applied to Universal Forwarders and it's related to wineventlogs because it's possible to apply a whitelist and/or a blacklist to the logs to ingest.

Ijn addition, avoid to put configurations in $SPLUNK_HOME/etc/system/local, but put always conf files in dedicated apps called Technical Add-ons (TAs) because in this way you can manage them with a Deployment Server, if instead you put conf files in systel local you have to manually manage them.

When you say "When I install heavy forwarders it worked deploying config files (under \etc\deploymentapps)." this means that you're using your Heavy Forwarder as a Deployment Server, but it isn't a good configuration if you have more than 50 client to manage because in this case you need a dedicated Deplyment Server.
You can find more information at https://docs.splunk.com/Documentation/Splunk/7.3.2/Updating/Aboutdeploymentserver .

Ciao.
Giuseppe

View solution in original post

0 Karma

CsungyiPepi19
New Member

mille grazie Giuseppe!

CsP

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi CsungyiPepi19,
logs can be filtered only on Indexers and (when present) on Heavy Forwarders as you can see at https://docs.splunk.com/Documentation/Splunk/7.3.2/Forwarding/Routeandfilterdatad.
There's only one filter that can be applied to Universal Forwarders and it's related to wineventlogs because it's possible to apply a whitelist and/or a blacklist to the logs to ingest.

Ijn addition, avoid to put configurations in $SPLUNK_HOME/etc/system/local, but put always conf files in dedicated apps called Technical Add-ons (TAs) because in this way you can manage them with a Deployment Server, if instead you put conf files in systel local you have to manually manage them.

When you say "When I install heavy forwarders it worked deploying config files (under \etc\deploymentapps)." this means that you're using your Heavy Forwarder as a Deployment Server, but it isn't a good configuration if you have more than 50 client to manage because in this case you need a dedicated Deplyment Server.
You can find more information at https://docs.splunk.com/Documentation/Splunk/7.3.2/Updating/Aboutdeploymentserver .

Ciao.
Giuseppe

0 Karma

CsungyiPepi19
New Member

Mille grazie Giuseppe!
CsP

0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...