Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

How to remove all events containing specific values in Splunk?

$
0
0
Hi All, Can any one guide me, on how to remove all events containing only the below listed events from rest of the events ? I am sure that we need to configure props.conf and transforms.conf , but not sure what to configure in props and how to right a regex in transforms.conf to remove the events . **Event Timestamp: April 24, 2017 12:54:34 Event Timestamp: April 24, 2017 12:55:30 Event Timestamp: April 24, 2017 12:56:34** Kindly guide me how to configure to remove the above events from rest of the events.

Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>