Do not rely on UI exclusion rules to control data egress or keep sensitive logs in house: move include/exclude regex rules and redaction to the agent config so unwanted lines never leave your systems. Use redaction templates for common PII patterns rather than trying to exclude everything after the fact. Re-check both the agent rules and the UI rules after upgrades, since the two layers behave differently.

Context: Mezmo's Agent 3.2 announcement documents a cost and privacy trap in UI-side exclusion rules. Exclusion rules configured in the Mezmo UI are applied only after ingestion, which means customers still pay egress for the unneeded log data, and logs containing PII can leave their system of origin before being excluded. The 3.2 agent instead supports inclusion and exclusion rules plus redaction via regex patterns applied at the agent, so filtered logs never leave the host.