<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I exclude log from sending to Splunk to save quota? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-exclude-log-from-sending-to-Splunk-to-save-quota/m-p/440062#M76749</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;The heart beat messages - Are you referring to messages from one splunk component to other? Because, splunk licensing doesn't count towards _internal logs. If not, please provide some sample events.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Aug 2018 19:25:41 GMT</pubDate>
    <dc:creator>sudosplunk</dc:creator>
    <dc:date>2018-08-30T19:25:41Z</dc:date>
    <item>
      <title>How do I exclude log from sending to Splunk to save quota?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-exclude-log-from-sending-to-Splunk-to-save-quota/m-p/440061#M76748</link>
      <description>&lt;P&gt;Hi guys. &lt;/P&gt;

&lt;P&gt;I have daily quota for 3G. but the log is too much. &lt;BR /&gt;
So, I'm trying to exclude some logs, like heart beat, to send to Splunk to save some usage. &lt;BR /&gt;
I'm trying to use Splunk Filter Rules:&lt;BR /&gt;
-&amp;gt; Exclude Patterns &lt;/P&gt;

&lt;P&gt;Some keywords I clicked exclude. &lt;BR /&gt;
But, i still am able to see these words when i search on Splunk. &lt;BR /&gt;
Can anyone help? Thanks. &lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 18:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-exclude-log-from-sending-to-Splunk-to-save-quota/m-p/440061#M76748</guid>
      <dc:creator>hakusama1024</dc:creator>
      <dc:date>2018-08-30T18:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: How do I exclude log from sending to Splunk to save quota?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-exclude-log-from-sending-to-Splunk-to-save-quota/m-p/440062#M76749</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;The heart beat messages - Are you referring to messages from one splunk component to other? Because, splunk licensing doesn't count towards _internal logs. If not, please provide some sample events.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 19:25:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-exclude-log-from-sending-to-Splunk-to-save-quota/m-p/440062#M76749</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-30T19:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do I exclude log from sending to Splunk to save quota?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-exclude-log-from-sending-to-Splunk-to-save-quota/m-p/440063#M76750</link>
      <description>&lt;P&gt;Hi @hakusama1024,&lt;/P&gt;

&lt;P&gt;I'm not really sure what you mean by "Exclude Patterns", but I can tell you about two ways to filter data before it gets indexed.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Either&lt;/STRONG&gt; you filter data at the source, which is the best option, because it doesn't generate additional log traffic:&lt;BR /&gt;
If you have a Universal Forwarder installed on a Linux System for example and you want to monitor all the files in /var/log/messages/ you could try to specify what particular files out of this file system you are interested in, by splitting up your single  monitoring stanza into multiple stanzas. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Or&lt;/STRONG&gt;,  if granular filtering at the source doesn't work you can filter at Indexer level (also at HF level).&lt;BR /&gt;
So you could actually filter out and throw away data that is matched via regular expression and avoid it getting indexed. &lt;/P&gt;

&lt;P&gt;I have a very good splunk answer from @lguinn  here:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/59370/filtering-events-using-nullqueue-1.html"&gt;https://answers.splunk.com/answers/59370/filtering-events-using-nullqueue-1.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This should help you understand how it can be done. &lt;/P&gt;

&lt;P&gt;If you give us additional information about the logfiles you want to filter out, we can assist you further.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 19:43:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-exclude-log-from-sending-to-Splunk-to-save-quota/m-p/440063#M76750</guid>
      <dc:creator>horsefez</dc:creator>
      <dc:date>2018-08-30T19:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I exclude log from sending to Splunk to save quota?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-exclude-log-from-sending-to-Splunk-to-save-quota/m-p/440064#M76751</link>
      <description>&lt;P&gt;hi @hakusama1024 ,&lt;/P&gt;

&lt;P&gt;Did @pyro_wood 's answer solve your problem? If so, please resolve this post by approving one of them. If not, keep us updated so that someone else can help solve your problem.&lt;/P&gt;

&lt;P&gt;Also, if you're feeling generous, give out an upvote to the user that helped ya. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 23:00:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-exclude-log-from-sending-to-Splunk-to-save-quota/m-p/440064#M76751</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-08-31T23:00:06Z</dc:date>
    </item>
  </channel>
</rss>

