Hello,
we indexing our application logs and i need to exclude some content from it
the log files looks like:
2015-07-09 00:00:01.1020|process-name|INFO| LINE TO EXCLUDE from index
2015-07-09 00:00:01.1021|process-name|INFO| Data OK
2015-07-09 00:00:01.1021|process-name|INFO| Data OK
2015-07-09 00:00:01.1021|process-name|INFO| Data OK
and i want to exclude all the contents with specific name that repeat itself
is it possible ?
Check out the answer below. Basically, you want to nullQueue
that event.
http://answers.splunk.com/answers/59370/filtering-events-using-nullqueue.html
The answer above is given for Windows logs, but the concepts are the same.