I have to exclude all subject with some similar set of words in subject.
Eg. Inc00452| RE: Exchange 2K16: Alert: Processor > % Processor Time
So I have to exclude all subject with 'Alert: Processor > % Processor Time'
So all subject with above keyword should be excluded
You probably meant to filter by event content, if so check here https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Routeandfilterdatad#Filter_event_data_...
and here
https://community.splunk.com/t5/Getting-Data-In/How-do-i-exclude-some-events-from-being-indexed-by-S...
Hi @priya0709 your question is not clear.. please provide us some more details, thanks.
My requirement is to exclude all subjects which has words "Alert: Processor > % Processor Time" in subject
Please see attached my query
Hi Priya, you were saying about logs ingestion at HF and filtering at HF?
or you were saying about the "alerts" email notification subject line?
Maybe, You could send a direct message here from your profile to me, so that we can understand and resolve your issue faster, thanks.
Please see attached