Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

Why am I not able to exclude events from getting indexed with my current props and transforms.conf?

$
0
0
Not able to exclude events from indexing on Splunk Enterprise Free version. Can anyone help me out here? Sample data: Name:mango Name:Mango Name:ManGo Name:apple Name:banana Name:strawberry Name:pineapple props.conf [txt1] DATETIME_CONFIG = CURRENT NO_BINARY_CHECK = true SHOULD_LINEMERGE = false category = Custom pulldown_type = true TRANSFORMS-set= setnull transforms.conf [setnull] REGEX = mango DEST_KEY = queue FORMAT = nullQueue

Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>