Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to configure nullQueue to filter out repetitive lines from a log file before indexing?

$
0
0
Splunk 6.1 Linux indexers feeding server with master license. I am trying to filter out repetitive lines from a log file before they are indexed. Need to configure the 3 conf files: inputs, props and transform. The server where the log file is located(different from indexer server where conf files are located): mmd5 mmd5 path/log: `/var/log/*/CheckPointReconciler.log*` Log line I want to filter out to nullQueue ( filter on 'Reading') 2015-12-30 2:02:12.736 14181:4 INFO job_id none main Reading checkpoint directory /mm/feeder/chkpt

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>