is there a way to exclude all logs being indexed for a certain field
for eg : sourcetype=azs container_name=moss-logger
I want my HF to filter any data being ingested from particular field (conatiner_name) with value "moss-logger"
Hi @vishetty,
you can discard (and not index) data before indexing but you cannot use fields to filter them, you have to find a regex and discard all the events that match that regex.
For more infos see at https://docs.splunk.com/Documentation/Splunk/8.2.2/Forwarding/Routeandfilterdatad#Filter_event_data_...
Ciao.
Giuseppe