If you mean Null: Non-existent value. Use:device.type = 'ABC' &&
device.ip = 10.20.30.40 && action exists If you are using the reporting
engine. Use a then clause to filter these out: filter_out (string
filter, string field)filter_out('null', 'action...
First off. Stop 10.200.50.11 from sending logs. Stop all hosts from
sending non-RFC compliant syslog. This will clear up those errors.
Second of all, run: du -ch /var/log This will show the disk space, this
partition should not fill up. You are most ...