I'm trying to create an admission rule in workload management with the following syntax:
any search with "=*" in the index will return a predefined message.
my intention is to block any search that contains "=*" in any part of the index, such as: "index=splun*", "index=spl*", "index=_internal*", etc.
I didn't find anything in the documentation that talked about it. Is there any way to create a general rule for this case?
That use case is not supported by WLM admission rules. Go to https://ideas.splunk.com to make a case for it.
That use case is not supported by WLM admission rules. Go to https://ideas.splunk.com to make a case for it.