Quantcast
Viewing all articles
Browse latest Browse all 47296

Discarding Events fron cron.log

On my univesal forwarder I have a repeated entry in my cron.log file that I would like to discard however I am not very familiar with regex terms. The entry in cron.log is hostname CROND[27158]: (root) CMD (/bin/sh /etc/init.d/swiagentd swrestart > /dev/null 2&>1) I have followed the instructions at: https://docs.splunk.com/Documentation/Splunk/6.5.2/Forwarding/Routeandfilterdatad#Discard_specific_events_and_keep_the_rest and I am using the following: props.conf [source::/var/log/cron] TRANSFORMS-null= setnull transforms.conf [setnull] REGEX = swrestart DEST_KEY = queue FORMAT = nullQueue I have restarted but I am still getting the message in my search. Do I have the correct regex? and is there a specific place in each .conf file that I should put the stanzas.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>