<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Searching w/o Indexing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Searching-w-o-Indexing/m-p/94598#M19682</link>
    <description>&lt;P&gt;Is there a way to access SplunkWeb without turning on indexing?  My license just got crushed by a security audit team, and we're going way over our license each day as the logs play catch-up.  After a while it should return to normal, but is there any way to access the data by say, stopping indexing before I go over the license limit?&lt;/P&gt;</description>
    <pubDate>Fri, 16 Mar 2012 14:00:21 GMT</pubDate>
    <dc:creator>jam678</dc:creator>
    <dc:date>2012-03-16T14:00:21Z</dc:date>
    <item>
      <title>Searching w/o Indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Searching-w-o-Indexing/m-p/94598#M19682</link>
      <description>&lt;P&gt;Is there a way to access SplunkWeb without turning on indexing?  My license just got crushed by a security audit team, and we're going way over our license each day as the logs play catch-up.  After a while it should return to normal, but is there any way to access the data by say, stopping indexing before I go over the license limit?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2012 14:00:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Searching-w-o-Indexing/m-p/94598#M19682</guid>
      <dc:creator>jam678</dc:creator>
      <dc:date>2012-03-16T14:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Searching w/o Indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Searching-w-o-Indexing/m-p/94599#M19683</link>
      <description>&lt;P&gt;Not really, but I think there is a better way to resolve this situation than turning off indexing. If you're an enterprise customer you're allowed 5 violations within a 30 day rolling window, so a couple of violations shouldn't be a big deal. Additionally, running with the same presumption, you can request a license reset from support/sales. &lt;/P&gt;

&lt;P&gt;The thing to do here is determine what is causing the violations with the searches you can find here: &lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume"&gt;http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Take a look at the section that says 'Quick summary information by host, source, source type, and index', it'll give you some searches that will identify broadly the areas where you're volume is being used. &lt;/P&gt;

&lt;P&gt;From there use the information at this link to route unnecessary &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The section you're looking for is  'Filter event data and send to queues'.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;You can eliminate unwanted data by routing it to nullQueue, Splunk's /dev/null equivalent. When you filter out data in this way, the filtered data is not forwarded or added to the Splunk index at all, and doesn't count toward your indexing volume. 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 16 Mar 2012 14:22:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Searching-w-o-Indexing/m-p/94599#M19683</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2012-03-16T14:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Searching w/o Indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Searching-w-o-Indexing/m-p/94600#M19684</link>
      <description>&lt;P&gt;Thanks, that should work - didn't know about directing data to /dev/null, that should be a huge help.  &lt;/P&gt;

&lt;P&gt;There aren't any limitations to how much over the license you can go in one day, right? Say I have a 10GB License, I can index, say, 50GB that one day as long as I don't do it 5 times over 30 days?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2012 12:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Searching-w-o-Indexing/m-p/94600#M19684</guid>
      <dc:creator>jam678</dc:creator>
      <dc:date>2012-03-19T12:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Searching w/o Indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Searching-w-o-Indexing/m-p/94601#M19685</link>
      <description>&lt;P&gt;Your understanding is correct, you won't stop indexing at whatever your indexing limit is, just incur a violation. Even if you had 6 violations, search would be the only thing affected.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2012 12:57:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Searching-w-o-Indexing/m-p/94601#M19685</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2012-03-19T12:57:16Z</dc:date>
    </item>
  </channel>
</rss>

