You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk Enterprise配置:过滤特定用户的审计日志冗余事件以控制数据量

Splunk Enterprise配置:过滤特定用户的审计日志冗余事件以控制数据量

Hey there! Let me walk you through exactly how to filter out those unwanted audit log events for that specific user—you’re totally on the right track using props.conf and transforms.conf on your indexer. This is a go-to method for targeted event filtering without messing with other important data.

配置核心思路

We’ll break this into three simple steps:

  1. Tell Splunk which audit log sourcetype we’re targeting
  2. Write a rule to match only events from that problematic user
  3. Route those matched events to the "null queue" so they never get indexed (saving your license quota!)

具体配置步骤

1. 编辑 props.conf(在索引器上操作)

First, open up $SPLUNK_HOME/etc/system/local/props.conf (or the app-specific props.conf if you’re using a dedicated audit app) and add this section:

[your_audit_sourcetype]
TRANSFORMS-drop_unwanted_user = drop_specific_user_events
  • Replace your_audit_sourcetype with the actual sourcetype of your Linux audit logs—you can find this by running a quick search in Splunk like index=* sourcetype=* audit to see what’s being used (common values are linux:audit or auditd).
  • The TRANSFORMS- name is just a label for our rule; feel free to name it something more descriptive if you want.

2. 编辑 transforms.conf(同样在索引器上)

Next, open $SPLUNK_HOME/etc/system/local/transforms.conf and add the filtering rule itself:

[drop_specific_user_events]
REGEX = user=your_target_username|auid=your_target_user_uid
DEST_KEY = queue
FORMAT = nullQueue

Let’s break this down so you understand every part:

  • REGEX: This is the pattern that snags events from your specific user. You’ll need to tweak this to match how the user shows up in your logs:
    • If your logs have lines like user=appcron, use REGEX = user=appcron
    • If they use the audit UID (like auid=1005), use REGEX = auid=1005
    • Use the | character if you need to match multiple identifiers for the same user
  • DEST_KEY = queue: Tells Splunk we want to change where this event gets sent
  • FORMAT = nullQueue: This is the magic line—any event matching our regex gets sent here, meaning it won’t be indexed at all.

3. 验证配置并重启Splunk

Before we wrap up, let’s make sure we didn’t make any syntax mistakes. Run these commands on your indexer:

$SPLUNK_HOME/bin/splunk btool props list --debug | grep drop_unwanted_user
$SPLUNK_HOME/bin/splunk btool transforms list --debug | grep drop_specific_user_events

If no errors pop up, restart your Splunk indexer to apply the changes:

$SPLUNK_HOME/bin/splunk restart

几个关键提醒

  • Test first! Before letting this run full-time, you can temporarily swap nullQueue with indexQueue and run a search to confirm only the right events are being matched. Switch it back once you’re confident.
  • Double-check your regex! Use Splunk’s search bar to test your pattern first, like:
    index=your_audit_index sourcetype=your_audit_sourcetype | regex "user=your_target_username"
    
    This shows exactly which events would be filtered—adjust the regex if it’s catching too much (or too little).
  • Keep configs organized: If you’re managing multiple apps, it’s better to put these configs in the app’s local directory instead of system/local to avoid confusion later.

备注:内容来源于stack exchange,提问作者Egyas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 11:34:39