Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

How can i retreive only some fields ?

$
0
0

Hi i'm using this app and i have some trouble to reduce the indexed volume

i will reduce the flow selecting only some fields : i modified the file fw1-loggrabber.conf : FIELDS="time;action;src;s_port;dst;service" but it's not working : flow not contain selected fields "loc=109418|time=18Jul2013 10:30:54|action=accept|orig=10.127.**|i/f_dir=inbound|i/f_name=bond1.206"

when i reset config file i receive all fields

"loc=5384|time=18Jul2013  5:59:59|action=accept|orig=10.127.**|i/f_dir=inbound|i/f_name=Exp1-2|has_accounting=0|uuid=<51e7683f,00000004,11017f0a,0005ffff>|product=VPN-1 & FireWall-1|__policy_id_tag=product=VPN-1 & FireWall-1[db_tag={66154744-EF02-11E2-936D-000000005656};mgmt;date=1374080435;policy_name=INTE]|rule=12|rule_uid={131EB010--AA76-1DE2C9866C7B}|service_id=TCP-9505|src=10.156.4.10|s_port=2110|dst=10.176.253.182|service=9505|proto=tcp"

i read someone use old binary version 2.0.1 to solve this issue where can i download the older version 2.0.1 ?

someone have got any other solution ?

Thanks


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>