Splunk Enterprise

SPLUNK Forwarders: is there a way to forward types of files in one folder selectively?

lbraginsky
New Member

Hello,

I'm trying to limit the amount of data that SPLUNK indexes daily and I noticed that a bunch of our server log files contain lots of reduntant data and hence can be skipped. HOWEVER, the "useless" files live in the same folders as some of the "useful" files. Question: is there a way to segregate files that Forwarders pick up from the same directory (we have both Windows and Linux servers)?

Thanks,

leo

Tags (1)
0 Karma

Ayn
Legend

Sure. Check out the whitelisting/blacklisting mechanisms in inputs.conf.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...