#Filtering syslog. . .
1 messages · Page 1 of 1 (latest)
You can add an exclude to your event filter and specify that event name:
event filter rule add -type exclude -filter-name customized-filter -message-name event.name.*
What message in the catalog equates to kern_audit?