Getting Data In

Don't store "success" log entries

Engager

Is there a way to make it so Splunk will discard a log entry that comes in with a certain substring in the message such as "The job succeeded"? We have an MSSQL server that is taking up a huge amount of disk space with log entries saying that one of the scheduled jobs completed. We have some SQL jobs that are scheduled to run every second.

Tags (1)

Motivator

Hi jmorello

You can route unwanted events to the nullQueue

Have a look at this answer:

http://splunk-base.splunk.com/answers/11617/route-unwanted-logs-to-a-null-queue