You can filter out those syslog messages you don't want and route them to the null queue so they wont be indexed.
props.conf
[syslog_sourcetype]
TRANSFORMS-null= syslogfilter
transforms.conf
[syslogfilter]
REGEX = ^.+process\[\d+\]:$
DEST_KEY = queue
FORMAT = nullQueue
Check out this link at Splunk docs for more details
... View more