Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How can I filter events befoer they are indexed so they aren't indexed?

$
0
0
I tried this solution but no success. I am trying to filter data from being indexed.I need only the Error events In props conf: [source:://C:\\Windows\\System32\\winevt\\Logs] # Transforms must be applied in this order # to make sure events are dropped on the # floor prior to making their way to the # index processor TRANSFORMS-set = setnull, setparsing In transforms.conf: [setnull] REGEX = . DEST_KEY = queue FORMAT = nullQueue [setparsing] REGEX = Error DEST_KEY = queue FORMAT = indexQueue

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>