is there a way in Splunk to index only the event of a log files that contains a specific expression or doesn't contains it.
By example, if I index a very big logfile, i don't want to index in it the INFO event but only the ERROR events.
yes, there is a way to do this in Splunk. You can filter events according to their content and route it to different Splunk Queues or indexes or 3rd Party Systems.
Docs is your friend, please see this
hope this helps to get you started ...