We are using the Splunk Universal Forwarder on Windows servers to capture event viewer logs into Splunk. We have a known issue with a product causing a large number of events to be recorded in the event viewer which are then sent into Splunk. How can we filter out a specific event from the Universal Forwarder so that it is not sent into Splunk?
See this document.
https://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf#Event_Log_filtering
Just be aware that there are two different formats and you use one of them depending on whether you ingest your events in "old style" plain text format or as XML.