All Apps and Add-ons

Splunk Add-on for AWS: Is there any way to exclude a specific types of events from indexing?

rayar
Contributor

We have the add on installed, is there any way to exclude a specific types of events from indexing ?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

are you speaking of a Splunk Cloud environment or a Splunk Enterprise on premise?

if Splunk Enterprise on premise, you can follow the instructions at https://docs.splunk.com/Documentation/Splunk/9.0.2/Forwarding/Routeandfilterdatad#Filter_event_data_...

If Splunk Cloud, You have to ask to Splunk Support..

Ciao.

Giuseppe

0 Karma

rayar
Contributor

we are on Splunk Enterprise on premise

is there an option to exclude those events in Splunk Add-on for AWS also ?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

no, there isn't any option, only filtering as described in the above link.

Ciao.

Giuseppe

0 Karma

rayar
Contributor

Thanks a lot , I was able to filter the data 

1 more question , how I can define monitoring stanza for s3://aws-controltower-logs-272341124329 .....

I have tested with 

[source::.../aws-controltower-logs-272341124329*/.../*.json.gz]

but I want to add s3://

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

I never tried  because I didn't have the necessity to ingest s3 logs and I usually prefer to use sourcetype instead source and, if possible, I hint to use it so you haven't this problem.

Anyway, you could try with * or consider that stanza a regx, so you could escape (with backslash) the first chars.

Ciao.

Giuseppe

0 Karma

rayar
Contributor

the question is how I mark // is part of the path 

I tried to \/\/ but it didn't work 

How to mark the specials characters 

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...