The only way to "reduce the production of logs" going into Splunk is to not log as much that the Universal Forwarder picks up, or that is sent via the HTTP Event Collector
If you want to filter events based on criteria in your SPL, then you need to look at the field(s) in question, and only select what you’re looking for
from User warren – Stack Overflow https://stackoverflow.com/questions/70924568/reduce-logging-for-retry-count-in-splunk/70941007#70941007
via IFTTT