Splunk Enterprise配置:过滤特定用户的审计日志冗余事件以控制数据量
Hey there! Let me walk you through exactly how to filter out those unwanted audit log events for that specific user—you’re totally on the right track using props.conf and transforms.conf on your indexer. This is a go-to method for targeted event filtering without messing with other important data.
配置核心思路
We’ll break this into three simple steps:
- Tell Splunk which audit log sourcetype we’re targeting
- Write a rule to match only events from that problematic user
- Route those matched events to the "null queue" so they never get indexed (saving your license quota!)
具体配置步骤
1. 编辑 props.conf(在索引器上操作)
First, open up $SPLUNK_HOME/etc/system/local/props.conf (or the app-specific props.conf if you’re using a dedicated audit app) and add this section:
[your_audit_sourcetype] TRANSFORMS-drop_unwanted_user = drop_specific_user_events
- Replace
your_audit_sourcetypewith the actual sourcetype of your Linux audit logs—you can find this by running a quick search in Splunk likeindex=* sourcetype=* auditto see what’s being used (common values arelinux:auditorauditd). - The
TRANSFORMS-name is just a label for our rule; feel free to name it something more descriptive if you want.
2. 编辑 transforms.conf(同样在索引器上)
Next, open $SPLUNK_HOME/etc/system/local/transforms.conf and add the filtering rule itself:
[drop_specific_user_events] REGEX = user=your_target_username|auid=your_target_user_uid DEST_KEY = queue FORMAT = nullQueue
Let’s break this down so you understand every part:
REGEX: This is the pattern that snags events from your specific user. You’ll need to tweak this to match how the user shows up in your logs:- If your logs have lines like
user=appcron, useREGEX = user=appcron - If they use the audit UID (like
auid=1005), useREGEX = auid=1005 - Use the
|character if you need to match multiple identifiers for the same user
- If your logs have lines like
DEST_KEY = queue: Tells Splunk we want to change where this event gets sentFORMAT = nullQueue: This is the magic line—any event matching our regex gets sent here, meaning it won’t be indexed at all.
3. 验证配置并重启Splunk
Before we wrap up, let’s make sure we didn’t make any syntax mistakes. Run these commands on your indexer:
$SPLUNK_HOME/bin/splunk btool props list --debug | grep drop_unwanted_user $SPLUNK_HOME/bin/splunk btool transforms list --debug | grep drop_specific_user_events
If no errors pop up, restart your Splunk indexer to apply the changes:
$SPLUNK_HOME/bin/splunk restart
几个关键提醒
- Test first! Before letting this run full-time, you can temporarily swap
nullQueuewithindexQueueand run a search to confirm only the right events are being matched. Switch it back once you’re confident. - Double-check your regex! Use Splunk’s search bar to test your pattern first, like:
This shows exactly which events would be filtered—adjust the regex if it’s catching too much (or too little).index=your_audit_index sourcetype=your_audit_sourcetype | regex "user=your_target_username" - Keep configs organized: If you’re managing multiple apps, it’s better to put these configs in the app’s local directory instead of
system/localto avoid confusion later.
备注:内容来源于stack exchange,提问作者Egyas

