Hi,
I'm having no luck getting a filter-n-drop setup...
I referenced https://docs.splunk.com/Documentation/Splunk/8.2.5/Forwarding/Routeandfilterdatad
props.conf
[source::/opt/fooBar/*]
TRANSFORMS-null = setnull
transforms.conf
[setnull]
REGEX = ^(DEBUG)
DEST_KEY = queue
FORMAT = nullQueue
I am not sure if the REGEX is correct, but "debug" is seen in ERROR events so I only want to capture and drop events where DEBUG is the first word...
Any help appreciated.
Thank you!
You don't need to capture the DEBUG word so regex of ^DEBUG would be sufficient.
But just for testing, remove the beginning of the line anchor, leave just DEBUG and check if it's working. It should match the word DEBUG anywhere in the event so if it doesn't work, the transform is not being applied.
Did you check the effective props and transforms with btool to check if it's not overwritten anywhere?
Is log level (DEBUG|INFO|ERROR etc) the first word in the raw event?
yes, show source shows DEBUG .... <rest of the line data>
Did you applied the configuration on Heavy forwarder (if you use one) OR indexer (if data directly comes from UF to indexer) ? Did you restart Splunk after applying change?
yes we did apply the confs on the HF, and yes we did restart
the events are sourcetype=catalina,
should I try using this combo under
[catalina] ?
or do you think the regex is bad?
maybe there is something hidden in the raw...
REGEX = *DEBUG* ?
IDK
You don't need to capture the DEBUG word so regex of ^DEBUG would be sufficient.
But just for testing, remove the beginning of the line anchor, leave just DEBUG and check if it's working. It should match the word DEBUG anywhere in the event so if it doesn't work, the transform is not being applied.
Did you check the effective props and transforms with btool to check if it's not overwritten anywhere?
We tried your suggestions but still no luck.
We will poke around with btool to find the issue.
Thankyou
Thank you, we found the issue.
Your suggestions were helpful.