Getting Data In

Filter splunk data to reduce ingestion size

splunk2xconnect
Observer

We are transferring log using log drains and using token created using HTTP event collector.  We need to filter data entering into splunk cloud logs. Few keywords we want to eliminate all-together so reduced the size of our ingestion. So around 50% of the data being ingested is not required and its coming from third party which don't have controllable log levels. How can we avoid data by these keywords and prevent it being ingested into splunk. Or is there way to filter data after we get the data in splunk to reduce the ingestion size ? 

Thanks,Dee

Labels (1)
0 Karma

gbansode
Explorer
0 Karma

PickleRick
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...