I"d like to send audit data through an event hub. However, i want my heavy fwd'r to not send all fields to splunk as 75% of is will be useless and take up all my ingesting quota.
Is there an easy way to do this? The data coming in is Azure SQL where i don't beleive i can change data going into the hub.
If you want to discard entire events, see https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Routeandfilterdatad#Filter_event_data_...
If you want to discard parts of events, use SEDCMD in props.conf.
[mysourcetype] SEDCMD-winevent = s/This event is generated.*//