Getting Data In

How to exclude certain fields in json logs from being displayed on UI OR being indexed?


Hi All,

Is there a way to exclude certain fields from my JSON data? For example: I have the below JSON Format event with fields A , B and C.


A : XXXX..
B : YYYY...
C : ZZZZ....


Is there a way to remove the fields B and C along with its values from the search result?


You can use SEDCMD to replace with empty strings. See if this link helps


[sourcetype stanza]
SEDCMD-removefieldB = s/B:\w+//g
SEDCMD-removefieldC = s/C:\w+//g


Thankyou @sundareshr

0 Karma

Ultra Champion

@saranya_fmr, if you accept this answer, please mark the "accept" link and @sarnagar will get delicious karma points and the rest of us will know this works as an answer.

0 Karma