Getting Data In

How to exclude certain fields in json logs from being displayed on UI OR being indexed?


Hi All,

Is there a way to exclude certain fields from my JSON data? For example: I have the below JSON Format event with fields A , B and C.


A : XXXX..
B : YYYY...
C : ZZZZ....


Is there a way to remove the fields B and C along with its values from the search result?


You can use SEDCMD to replace with empty strings. See if this link helps


[sourcetype stanza]
SEDCMD-removefieldB = s/B:\w+//g
SEDCMD-removefieldC = s/C:\w+//g


Thankyou @sundareshr

