As well as somesoni2's suggestion, you can also whitelist or blacklist particular transactions, using various methods.
The general term for that is "route to the null queue". Here's one example answer that explains hwo to do it in one situation.
https://answers.splunk.com/answers/11617/route-unwanted-logs-to-a-null-queue.html
In essence, you can either route only specific things to the nullqueue, or you can route everything to the nullqueue and then save the specific items you want to keep.
Of course, if your set it up so that the logs are never created, then you don't have to do that decisioning.
... View more