Hello - I want to send only events with keyword BIDPRICE from my application logs. I guess i need to modifiy props.conf, transforms.conf and outputs.conf
Can someone help me what changes are acually needed. fyi-Currently forwading is working fine without this filter.
Thanks in advance for help.
asked 25 Apr '12, 02:51
This is quite thoroughly discussed in the docs, please see: http://docs.splunk.com/Documentation/Splunk/4.3.1/Deploy/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest
If you have a heavy forwarder, the settings should be placed there. In all other cases, the settings should be on the indexer.
In short, what you need to do is
What this does is to apply a set of rules to your incoming data. First, in props.conf you tell splunk that all events of a certain sourcetype should pass through a transform (or in this case, two transforms -
Then, in transforms.conf, you state how data should be treated.
If this does not work for you, then please tell us more about your setup, and post the relevant parts of props.conf and transforms.conf, along with a few sample events from your application log file.
You should know though that this will only work for new data coming in, and not alter any existing events already in your index.
Think of it as saying
So what happens when use
Hope this helps,
If these are light or universal forwarder, you cannot filter the logs there. You'll have to do it at the indexer instead. Instructions on how to do this are available in the docs: http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Filter_event_data_and_send_to_queues
answered 25 Apr '12, 02:58