How do i exclude paticular sourcetype from being indexed at my indexer end
Or is there any method to stop them at forwarder end
you can stop ingestion inserting disabled=1 in each stanza of your sourcetype in your forwarders inputs.conf, this is easy if you have not many Forwarders or a Deployment Server.
Otherwise, if you want to filter them on the indexers, you have to insert:
and in transforms.conf
and restart Splunk
When you want to disable filter, you have only to comment (#) the TRANSFORMS command in props.conf (obviously restarting Splunk!).
View solution in original post