Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

Why is my Splunk 6.2.5 Heavy Forwarder not filtering out events as expected?

$
0
0
My Heavy Forwarder forwards data to the indexer fine, however, I wanted to filter out some events before being forwarded using props.conf and transforms.conf, but the indexer still receives everything. props.conf: [source::/var/log/vsftpd.log] TRANSFORMS-null = setnull transforms.conf: [setnull] REGEX = 220 DEST_KEY = queue FORMAT = nullQueue for testing, I just simplified the REGEX to filter out all events containing "220" I even tried `REGEX = .` (to filter out everything) but still had no effect. What am I missing? I'm using Splunk 6.2.5 BTW.

Viewing all articles
Browse latest Browse all 727

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>