Hello,
I have the same problem :S
noybin did you find the fix to filter events (5156)?
I treid with blacklist, whitelist and the events are still indexed :S
props.conf and transforms.conf didn't fix the problem for me :S
Splunk Version: 6.2.1
Splunk Build: 245427
... View more