I have to exclude all subject with some similar set of words in subject.
Eg. Inc00452| RE: Exchange 2K16: Alert: Processor > % Processor Time
So I have to exclude all subject with 'Alert: Processor > % Processor Time'
So all subject with above keyword should be excluded
You probably meant to filter by event content, if so check here https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Routeandfilterdatad#Filter_event_data_...
Hi @priya0709 your question is not clear.. please provide us some more details, thanks.
Hi Priya, you were saying about logs ingestion at HF and filtering at HF?
or you were saying about the "alerts" email notification subject line?
Maybe, You could send a direct message here from your profile to me, so that we can understand and resolve your issue faster, thanks.