Hi ,
I am facing a weird issue - where on a Splunk indexer I am trying to filter out log events using props and transforms file.
I have noticed that filtering of log events works perfectly fine for sourcetypes which are not defined or do not exsist in Splunk default config. For example Okta, Jenkins,fluentd etc.
As soon as I try to filter IIS/Catalina sourcetype - it never works .
For example this is my props - which is filtering journald sourcetype but not iis
Props
[iis]
TRANSFORMS-routing = setnull
[journald]
TRANSFORMS-routing = setnull
Transforms
[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
Do
splunk btool props list --debug
(Or "list props"; I can never remember the proper order of those)
And see what is the effective configuration for your sourcetype and where it's defined