Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

Why isn't this regex working on /var/log?

$
0
0
Hi, I'm using a Single Instance of Splunk 6.6.2 and I've tried filtering some events of my log using the code below, but the filter doesn't work. I put this argument **"[\dbus\]"** into regex because I don't want this to be indexed. What's wrong with this? **inputs.conf:** [source::/var/log/messages] disabled = 0 index = main sourcetype = my_sourcetype **props.conf:** [my_sourcetype] TRANSFORMS-null = setnull **transforms.conf:** [setnull] REGEX = \[dbus\] DEST_KEY = queue FORMAT = nullQueue

Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>