Getting Data In

How to exclude certain logs from indexing

vishetty
Observer

is there a way to exclude all logs being indexed for a certain field 

for eg : sourcetype=azs  container_name=moss-logger

I want my HF to filter any data being ingested from particular field (conatiner_name) with value "moss-logger"

Labels (4)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @vishetty,

you can discard (and not index) data before indexing but you cannot use fields to filter them, you have to find a regex and discard all the events that match that regex.

For more infos see at https://docs.splunk.com/Documentation/Splunk/8.2.2/Forwarding/Routeandfilterdatad#Filter_event_data_...

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...

The Visibility Gap: Hybrid Networks and IT Services

The most forward thinking enterprises among us see their network as much more than infrastructure – it's their ...

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...