<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter splunk data to reduce ingestion size in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Filter-splunk-data-to-reduce-ingestion-size/m-p/578935#M102201</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241625"&gt;@splunk2xconnect&lt;/a&gt;&amp;nbsp;Please refer&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Filtering-events-using-NullQueue/m-p/66392" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Filtering-events-using-NullQueue/m-p/66392&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Dec 2021 15:19:22 GMT</pubDate>
    <dc:creator>gbansode</dc:creator>
    <dc:date>2021-12-20T15:19:22Z</dc:date>
    <item>
      <title>Filter splunk data to reduce ingestion size</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-splunk-data-to-reduce-ingestion-size/m-p/578906#M102198</link>
      <description>&lt;P&gt;We are transferring log using log drains and using token created using HTTP event collector.&amp;nbsp; We need to filter data entering into splunk cloud logs. Few keywords we want to eliminate all-together so reduced the size of our ingestion. So around 50% of the data being ingested is not required and its coming from third party which don't have controllable log levels. How can we avoid data by these keywords and prevent it being ingested into splunk. Or is there way to filter data after we get the data in splunk to reduce the ingestion size ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,Dee&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 12:23:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-splunk-data-to-reduce-ingestion-size/m-p/578906#M102198</guid>
      <dc:creator>splunk2xconnect</dc:creator>
      <dc:date>2021-12-20T12:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Filter splunk data to reduce ingestion size</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-splunk-data-to-reduce-ingestion-size/m-p/578909#M102199</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/Forwarding/Routeandfilterdatad" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.3/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 12:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-splunk-data-to-reduce-ingestion-size/m-p/578909#M102199</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-12-20T12:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Filter splunk data to reduce ingestion size</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-splunk-data-to-reduce-ingestion-size/m-p/578935#M102201</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241625"&gt;@splunk2xconnect&lt;/a&gt;&amp;nbsp;Please refer&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Filtering-events-using-NullQueue/m-p/66392" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Filtering-events-using-NullQueue/m-p/66392&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 15:19:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-splunk-data-to-reduce-ingestion-size/m-p/578935#M102201</guid>
      <dc:creator>gbansode</dc:creator>
      <dc:date>2021-12-20T15:19:22Z</dc:date>
    </item>
  </channel>
</rss>

