All Apps and Add-ons

Can I choose what to index in Splunk?

satoshi86
Engager

Hello to all Splunk wizards,

I would like to know if it is possible for me to choose what data to index in Splunk. The reason behind it is to limit the license usage of the Splunk server.

I currently owned a 2GB licensed daily volume, but once I've started monitoring the Fortigate firewall (syslog enabled), it consumes the license's quota till it reaches a violation.

What I'm thinking of doing is to only index the "status = deny" in order to limit the licensed daily volume.

Thanks.

0 Karma
1 Solution

satoshi86
Engager

sriousx : It seems that my vendor is not experienced enough to control the severity level on the firewall. But I thank you for your input.

0 Karma

satoshi86
Engager

Thanks alot Ayn!!

0 Karma

srioux
Communicator

Can also change logging level on the originating box itself. We do this on a number of network devices (primarily Cisco), and it works just fine.

Vendor docs should have some portion on how to control syslog verbosity.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...