<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Discarding of Events based on some column value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Discarding-of-Events-based-on-some-column-value/m-p/166767#M186161</link>
    <description>&lt;P&gt;Please see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/Forwarding/Routeandfilterdatad"&gt;this&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;You can use regex patterns to match and set that to be dumped to nullQueue. &lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2014 18:50:37 GMT</pubDate>
    <dc:creator>theouhuios</dc:creator>
    <dc:date>2014-02-26T18:50:37Z</dc:date>
    <item>
      <title>Discarding of Events based on some column value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Discarding-of-Events-based-on-some-column-value/m-p/166766#M186160</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have a JSON file which has a key value pair. I want to discard the events which contains "Name":"John" ( I mean if "Name" column is having "John" value ). The events which contains this "John" name should be discarded or should not be indexed.&lt;/P&gt;

&lt;P&gt;Please let me know the possible ways !!&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Abhay&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 18:19:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Discarding-of-Events-based-on-some-column-value/m-p/166766#M186160</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2014-02-26T18:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Discarding of Events based on some column value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Discarding-of-Events-based-on-some-column-value/m-p/166767#M186161</link>
      <description>&lt;P&gt;Please see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/Forwarding/Routeandfilterdatad"&gt;this&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;You can use regex patterns to match and set that to be dumped to nullQueue. &lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 18:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Discarding-of-Events-based-on-some-column-value/m-p/166767#M186161</guid>
      <dc:creator>theouhuios</dc:creator>
      <dc:date>2014-02-26T18:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Discarding of Events based on some column value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Discarding-of-Events-based-on-some-column-value/m-p/166768#M186162</link>
      <description>&lt;P&gt;Thanks It is now working ..&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 08:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Discarding-of-Events-based-on-some-column-value/m-p/166768#M186162</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2014-02-27T08:59:35Z</dc:date>
    </item>
  </channel>
</rss>

