Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

I want to remove my unwanted logs into nullQueue.But no luck

$
0
0
#### #### #### #### 2020-05-12 14:34:52,060 2020-05-12 14:34:52,060 2020-05-12 14:34:52,060 I want to remove ####< from my events, so i used props.conf along with transforms.conf with this below setting. But still ####< is not removed from the events. My props.conf [hast_sourcetype] BREAK_ONLY_BEFORE_DATE = CHARSET = UTF-8 DATETIME_CONFIG = LINE_BREAKER = ([\r\n]+) MAX_TIMESTAMP_LOOKAHEAD = 29 NO_BINARY_CHECK = true SHOULD_LINEMERGE = false TRANSFORMS-remove-hash = include-date-item category = Custom description = hash_sourcetype pulldown_type = true My transforms.conf [eliminate-hash-item] DELIMS = ####< DEST_KEY=queue FORMAT=nullQueue Please help me to solve this issue.

Viewing all articles
Browse latest Browse all 47296

Latest Images

Trending Articles



Latest Images