All Apps and Add-ons

Can I choose what to index in Splunk?

satoshi86
Engager

Hello to all Splunk wizards,

I would like to know if it is possible for me to choose what data to index in Splunk. The reason behind it is to limit the license usage of the Splunk server.

I currently owned a 2GB licensed daily volume, but once I've started monitoring the Fortigate firewall (syslog enabled), it consumes the license's quota till it reaches a violation.

What I'm thinking of doing is to only index the "status = deny" in order to limit the licensed daily volume.

Thanks.

0 Karma
1 Solution

satoshi86
Engager

sriousx : It seems that my vendor is not experienced enough to control the severity level on the firewall. But I thank you for your input.

0 Karma

satoshi86
Engager

Thanks alot Ayn!!

0 Karma

srioux
Communicator

Can also change logging level on the originating box itself. We do this on a number of network devices (primarily Cisco), and it works just fine.

Vendor docs should have some portion on how to control syslog verbosity.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...