Is there a way to exclude certain fields from my JSON data? For example: I have the below JSON Format event with fields A , B and C.
A : XXXX..
B : YYYY...
C : ZZZZ....
Is there a way to remove the fields B and C along with its values from the search result?
You can use
SEDCMD to replace with empty strings. See if this link helps
[sourcetype stanza] SEDCMD-removefieldB = s/B:\w+//g SEDCMD-removefieldC = s/C:\w+//g