filtering

noun

The action of limiting a set of events or fields within events by imposing criteria on them.

In the context of forwarding, you can filter and route events to specified indexers or queues. In the context of searching, you can construct searches that filter search results to remove unwanted events or fields. In addition, certain configuration files, such as inputs.conf and serverclass.conf provide attributes that allow you to impose whitelist and blacklist filtering rules for various purposes.

For more information

In the Search Manual:

In the Distributed Deployment Manual:

In the Getting Data In Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time