I would like to be able to blacklist certain hosts that have the universal forwarder on them from indexing because its killing my license and I don't have the budget to buy more at the moment. I also don't want to have to log into each machine and stop the splunk service.