All Apps and Add-ons

Can I choose what to index in Splunk?

satoshi86
Engager

Hello to all Splunk wizards,

I would like to know if it is possible for me to choose what data to index in Splunk. The reason behind it is to limit the license usage of the Splunk server.

I currently owned a 2GB licensed daily volume, but once I've started monitoring the Fortigate firewall (syslog enabled), it consumes the license's quota till it reaches a violation.

What I'm thinking of doing is to only index the "status = deny" in order to limit the licensed daily volume.

Thanks.

0 Karma
1 Solution

satoshi86
Engager

sriousx : It seems that my vendor is not experienced enough to control the severity level on the firewall. But I thank you for your input.

0 Karma

satoshi86
Engager

Thanks alot Ayn!!

0 Karma

srioux
Communicator

Can also change logging level on the originating box itself. We do this on a number of network devices (primarily Cisco), and it works just fine.

Vendor docs should have some portion on how to control syslog verbosity.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...