Try this method:
https://answers.splunk.com/answers/109253/how-to-filter-or-extract-fields-before-indexing-time.html
I have tested this with a CSV file and it works.
SAMPLE DATA
field1,field2,field3,field4
a1,a2,a3,a4
b1,b2,b3,b4
c1,c2,c3,c4
props.conf
[excludefields_ex]
TRANSFORMS-somefields = somefields
transforms.conf
[somefields]
DEST_KEY = _raw
REGEX = (\S+),(\S+),(\S+),(\S+)
FORMAT = $1 $3
Thanks you! It really works