How to drop or skip certain log events


(Suresh Kumar Kumaresan) #1

Hi

In Splunk, there is an option to skip/drop log events based on the regular expansion pattern.

For example, we would like to exclude heartbeat.jsp log events from getting indexed in Graylog.

Do we have this option in Graylog2, if yes could you please share some doc links or details?

Thanks
Suresh


(Jochen) #2

Yes, you can drop messages in a pipeline rule: http://docs.graylog.org/en/2.2/pages/pipelines/functions.html#drop-message


(Suresh Kumar Kumaresan) #3

Thanks a lot @jochen


(system) #4

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.