Getting Data In

Hide an entry

rlocone
New Member

Hello All,

I'm seeing a lot of port 68 broadcast from the WAN side. This is normal for a someone on a cable network. Is there a way that I can tell Splunk not to log these and drop the entries all together?

Thanks for your time and attention,

0 Karma

sdaniels
Splunk Employee
Splunk Employee

You can route data to the null queue to avoid having it stored or seen in Splunk. See the doc link below.

http://docs.splunk.com/Documentation/Splunk/6.0.1/Forwarding/Routeandfilterdatad#Discard_specific_ev...

lguinn2
Legend

Or Google "Splunk filter event data null queue"

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...