I have multiple hosts sending syslog information to splunk via its listener. However, one of these hosts, I'd like to on retain certain information.
Is the process the same (props.conf, transforms.conf) for filtering only a specific hosts syslog events?