Getting Data In

Hide an entry

rlocone
New Member

Hello All,

I'm seeing a lot of port 68 broadcast from the WAN side. This is normal for a someone on a cable network. Is there a way that I can tell Splunk not to log these and drop the entries all together?

Thanks for your time and attention,

0 Karma

sdaniels
Splunk Employee
Splunk Employee

You can route data to the null queue to avoid having it stored or seen in Splunk. See the doc link below.

http://docs.splunk.com/Documentation/Splunk/6.0.1/Forwarding/Routeandfilterdatad#Discard_specific_ev...

lguinn2
Legend

Or Google "Splunk filter event data null queue"

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...