All Apps and Add-ons

Splunk Add-on for AWS: Is there any way to exclude a specific types of events from indexing?

rayar
Contributor

We have the add on installed, is there any way to exclude a specific types of events from indexing ?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

are you speaking of a Splunk Cloud environment or a Splunk Enterprise on premise?

if Splunk Enterprise on premise, you can follow the instructions at https://docs.splunk.com/Documentation/Splunk/9.0.2/Forwarding/Routeandfilterdatad#Filter_event_data_...

If Splunk Cloud, You have to ask to Splunk Support..

Ciao.

Giuseppe

0 Karma

rayar
Contributor

we are on Splunk Enterprise on premise

is there an option to exclude those events in Splunk Add-on for AWS also ?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

no, there isn't any option, only filtering as described in the above link.

Ciao.

Giuseppe

0 Karma

rayar
Contributor

Thanks a lot , I was able to filter the data 

1 more question , how I can define monitoring stanza for s3://aws-controltower-logs-272341124329 .....

I have tested with 

[source::.../aws-controltower-logs-272341124329*/.../*.json.gz]

but I want to add s3://

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

I never tried  because I didn't have the necessity to ingest s3 logs and I usually prefer to use sourcetype instead source and, if possible, I hint to use it so you haven't this problem.

Anyway, you could try with * or consider that stanza a regx, so you could escape (with backslash) the first chars.

Ciao.

Giuseppe

0 Karma

rayar
Contributor

the question is how I mark // is part of the path 

I tried to \/\/ but it didn't work 

How to mark the specials characters 

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...