Don't store "success" log entries


Is there a way to make it so Splunk will discard a log entry that comes in with a certain substring in the message such as "The job succeeded"? We have an MSSQL server that is taking up a huge amount of disk space with log entries saying that one of the scheduled jobs completed. We have some SQL jobs that are scheduled to run every second.

Hi jmorello

You can route unwanted events to the nullQueue

Have a look at this answer: