Getting Data In

Is there a way to filter only a certain type of log from websphere to get logged to splunk?

sowmyak
New Member

I'm trying to add debug and error logs from websphere to splunk, but it consuming a lot of space. My aim is to reduce the memory consumed, so I want to avoid unnecessary logs from wbsphere to enter the splunk. All my websphere logs are first saved in system.out file which is then redirected to splunk. Please suggest if there is a way to do this.

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi Sowmyak,
on the inputs.conf, you can add a whitelist to select the files or blacklist to filter out some files.
Let us know more info, like your current inputs.conf, to filter out filenames, etc.. so that we can help you on the inputs.conf update..

https://www.splunk.com/blog/2009/07/09/monitoring-input-files-with-a-white-list.html
http://www.splunk.com/base/Documentation/latest/Admin/WhitelistAndBlacklistRules

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...