data filtering

verb or noun

A more intensive version of data routing. Under data filtering, the forwarding Splunk server determines which data to send and filters out unwanted events before it sends them to the receiving Splunk server. It can be used in conjunction with data cloning and load balancing.

Enable filtering by configuring outputs.conf, transforms.conf and props.conf] on the forwarder.

Related terms

For more information

In the Distributed Deployment Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time