Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do you exclude all lines with INFO or WARN from being indexed?

$
0
0
I have been reading through a lot of the previous answers to exclusion, but none match what I need. I need to exclude all INFO and WARN lines from one of my indexes, so that they are never processed. Only the ERROR lines should be processed. I have this so far, but I'm not certain of a couple of things. One what should I have in the props file to complete it and two, do I need the in the transforms.conf file: PROPS.CONF TRANSFORMS-set = setnull, setparsing TRANSFORMS.CONF [setnull] REGEX = INFO, WARN DEST_KEY = queue FORMAT = nullQueue

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>