Getting Data In

Don't store "success" log entries

jmorello
Engager

Is there a way to make it so Splunk will discard a log entry that comes in with a certain substring in the message such as "The job succeeded"? We have an MSSQL server that is taking up a huge amount of disk space with log entries saying that one of the scheduled jobs completed. We have some SQL jobs that are scheduled to run every second.

Tags (1)

chris
Motivator

Hi jmorello

You can route unwanted events to the nullQueue

Have a look at this answer:

http://splunk-base.splunk.com/answers/11617/route-unwanted-logs-to-a-null-queue

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...