how can i modify the transforms.conf file so that when i ingest the data it throws away all the events that have the status FAILED after the first ip address
You need to identify these events and direct them to a null queue
how can i identify, because i have file with log events, and i need to ingest on splunk
Essentially you need a regex to identify the events you want to filter (or route)