Configuring conditional streaming
In an IBM Log Analysis instance, you can configure streaming exclusion rules through the UI to filter what data is streamed.
As of 28 March 2024 the IBM Log Analysis and IBM Cloud Activity Tracker services are deprecated and will no longer be supported as of 30 March 2025. Customers will need to migrate to IBM Cloud Logs, which replaces these two services, prior to 30 March 2025. For information about IBM Cloud Logs, see the IBM Cloud Logs documentation.
-
Log lines that match a streaming exclusion rule are not streamed.
-
When log lines are ingested, streaming exclusion rules are applied to log lines that are retained after the ingestion exclusion rules are applied.
You must have manager access to define exclusion rules.
Complete the following steps to define an exclusion rule:
Verify that each exclusion rule that you add behaves as expected. Improper configured exclusion rules can result in storing data not intended for storage.
-
Click the Settings icon . Then select Streaming > Exclusion Rules.
-
Select Add Rule. The Create a Rule section opens.
-
Enter a name for the rule in the section What is this rule for?
-
Enter the exclusion criteria by adding a query. For more information on how to build a query, see Select the set of events to display through a view by applying a search query.
-
Click Save.
-
After you configure an exclusion rule, verify that the exclusion rule behaves as you expect.
Check the query in a custom view by entering the search criteria in the search bar of the Everything view, and validating that the data that is displayed is the data that you want excluded.