Hi ,
I would like to know if we can use SPL commands on configuration files to filter incoming data ?
Cause using Regex is out of option.
https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/IngestEval
View solution in original post
This is eval, could i really use to filter the events before index time without using regex?
This works 🙂Using eval to input a index time field and identify which will be ingested or not.