Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Trying to filter ASA syslogs before indexing to avoid license violations, why are our props and transforms configurations not working?

$
0
0
I've created this filter and placed them in the config files mentioned below in the following directory: D:\Program Files (x86)\Splunk\etc\system\local props.conf [cisco:asa] TRANSFORMS-null = setnull transforms.conf [setnull] REGEX = (?=.*ASA-4-106100)(?=.\b(Built|Teardown|permitted)\b) DEST_KEY = queue FORMAT = nullQueue The filter doesn't seem to work. Anyone have any suggestions? Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>