Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

How to filter specific fields in structured events in Heavy Forwarder?

$
0
0
Hi Gaurav I want to know how to filter only few fields in an event and eliminate the other fields. Eg: { [-] action: ALLOW formatVersion: 1 httpRequest: { [] } httpSourceId: 30gcfrxt8djgvhg4b8f074e httpSourceName: ALB nonTerminatingMatchingRules: [ [] ] rateBasedRuleList: [ [] ] ruleGroupList: [ [] ] terminatingRuleId: Default_Action terminatingRuleType: REGULAR timestamp: 1571993927624 webaclId: cxxxxxxxxxxxxxxxxxxxxxxxxxxx } I want only fields like action, ruleBasedRuleList, terminatingRuleType, and webaclId. How can I filter these fields in Splunk?

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>