Hello All,
I'm seeing a lot of port 68 broadcast from the WAN side. This is normal for a someone on a cable network. Is there a way that I can tell Splunk not to log these and drop the entries all together?
Thanks for your time and attention,
You can route data to the null queue to avoid having it stored or seen in Splunk. See the doc link below.
Or Google "Splunk filter event data null queue"