Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Eliminate logs before indexing

$
0
0
Hi, Someone can help me in filtering logs from Checkpoint before they are indexing? I tried follow that link: https://answers.splunk.com/answers/378972/how-to-filter-out-certain-events-from-checkpoint-d.html but I think my REGEX doesn't works. I need to ignore all events that the "message_info" field is equal to "Address spoofing", here is my props.conf and transforms.conf props.conf: [checkpoint:syslog] TRANSFORMS-null= setnullCheckpoint transforms.conf: [setnullCheckpoint] REGEX = message_info=Address spoofing DEST_KEY = queue FORMAT = nullQueue Thank you!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>