All Apps and Add-ons

Can I choose what to index in Splunk?

satoshi86
Engager

Hello to all Splunk wizards,

I would like to know if it is possible for me to choose what data to index in Splunk. The reason behind it is to limit the license usage of the Splunk server.

I currently owned a 2GB licensed daily volume, but once I've started monitoring the Fortigate firewall (syslog enabled), it consumes the license's quota till it reaches a violation.

What I'm thinking of doing is to only index the "status = deny" in order to limit the licensed daily volume.

Thanks.

0 Karma
1 Solution

satoshi86
Engager

sriousx : It seems that my vendor is not experienced enough to control the severity level on the firewall. But I thank you for your input.

0 Karma

satoshi86
Engager

Thanks alot Ayn!!

0 Karma

srioux
Communicator

Can also change logging level on the originating box itself. We do this on a number of network devices (primarily Cisco), and it works just fine.

Vendor docs should have some portion on how to control syslog verbosity.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...