I have an event that comes to the index.
| search index = indexname
filed1
field2
field3
I need to write an exception that will discard the field before getting into the index
output:
| search index = indexname
filed1
field3
Configure a null queue and direct events that you don't want to it https://docs.splunk.com/Documentation/Splunk/8.2.3/Forwarding/Routeandfilterdatad
If you can identify the events you don't want, you can send them to a null queue.
@ITWhisperer or so that the field values are immediately empty as soon as they get into the index
@ITWhisperer It is important for me that they do not come to the index. so that he throws them back.
Configure a null queue and direct events that you don't want to it https://docs.splunk.com/Documentation/Splunk/8.2.3/Forwarding/Routeandfilterdatad
[ActiveDirectory] TRANSFORMS-null= setnull
[setnull] REGEX = \[ms-Mcs-AdmPwdExpirationTime\] DEST_KEY = queue FORMAT = nullQueue