2

I see from this question and answer on Splunk's own Q&A site that it's possible to exclude certain messages from indexing on a Splunk instance.

I have a Splunk Cloud instance where the only way of configuring such things is through the GUI. I don't have access to edit the configuration files directly.

This answer (again on Splunk's site) discusses how to translate entries in props.conf into inputs to the GUI. However my particular case of filtering out messages entirely isn't covered.

How can I do this with the Splunk GUI?

Flup
  • 7,688
  • 1
  • 31
  • 43

1 Answers1

1

I've not used the cloud version sorry but if you install the 'full splunk' on your clients rather than the light-forwarder you can strip them out via props there so they don't get sent to the indexer at all, obviously you don't want your clients indexing too so just set it to forward everything and index nothing.

Chopper3
  • 100,240
  • 9
  • 106
  • 238