Answer by warren for Reduce logging for retry_count in splunk

The only way to "reduce the production of logs" going into Splunk is to not log as much that the Universal Forwarder picks up, or that is sent via the HTTP Event Collector

If you want to filter events based on criteria in your SPL, then you need to look at the field(s) in question, and only select what you’re looking for

from User warren – Stack Overflow https://stackoverflow.com/questions/70924568/reduce-logging-for-retry-count-in-splunk/70941007#70941007
via IFTTT