Is there anyway on Splunk search peer or Forwarder to filter the data. Like log messages that contain DEBUG or INFO should be filtered before getting indexed in Splunk?
yes, many ways, starting with monitor filtering while and black listing and all the way to filtering an routing with props.conf and transforms.conf
and some more specific to your use case answers:
hope it helps
View solution in original post
Depends on how you ingest docker logs, with the collectord you can annotate to drop some log lines, see https://www.outcoldsolutions.com/docs/monitoring-docker/v5/annotations/#example-2-dropping-messages