<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPLUNK index main logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108038#M22728</link>
    <description>&lt;P&gt;Thank you!!!&lt;/P&gt;</description>
    <pubDate>Mon, 21 Oct 2013 21:27:35 GMT</pubDate>
    <dc:creator>jviteka</dc:creator>
    <dc:date>2013-10-21T21:27:35Z</dc:date>
    <item>
      <title>SPLUNK index main logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108032#M22722</link>
      <description>&lt;P&gt;My Splunk License Usage app is showing that my SPLUNK server is using 26% of my license(From "main"). Is there any way to make this smaller?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2013 20:35:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108032#M22722</guid>
      <dc:creator>jviteka</dc:creator>
      <dc:date>2013-10-21T20:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK index main logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108033#M22723</link>
      <description>&lt;P&gt;I know that I can remove the monitor from /opt/splunk/var/log/splunk/*.log but would that be a good idea?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2013 20:38:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108033#M22723</guid>
      <dc:creator>jviteka</dc:creator>
      <dc:date>2013-10-21T20:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK index main logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108034#M22724</link>
      <description>&lt;P&gt;It would make no difference. These logs go to the &lt;CODE&gt;_internal&lt;/CODE&gt; index and do not count against your license.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2013 20:42:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108034#M22724</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-10-21T20:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK index main logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108035#M22725</link>
      <description>&lt;P&gt;So when i look at my domain host "SPLUNK01.My.Domain" and "main" they dont count against my license? Why does the "License Usage" app on the matrix they show?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2013 20:51:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108035#M22725</guid>
      <dc:creator>jviteka</dc:creator>
      <dc:date>2013-10-21T20:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK index main logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108036#M22726</link>
      <description>&lt;P&gt;Internal Splunk logs aren't sent to 'Main'.  they're sent to '_internal' and aren't applied to your license.  If you have data going into Main, it's because of inputs you may have set up.  &lt;/P&gt;

&lt;P&gt;Recommend looking at the data in your main index and making determinations from there.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2013 21:02:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108036#M22726</guid>
      <dc:creator>emiller42</dc:creator>
      <dc:date>2013-10-21T21:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK index main logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108037#M22727</link>
      <description>&lt;P&gt;Splunk indexes its internal logs (for example, &lt;CODE&gt;splunkd.log&lt;/CODE&gt;) into an index named &lt;CODE&gt;_internal&lt;/CODE&gt;. This index does &lt;EM&gt;not&lt;/EM&gt; count as part of your Splunk license. Splunk does not add any data to the &lt;CODE&gt;main&lt;/CODE&gt; index. So disabling Splunk's logs will not save you anything - as Ayn points out.&lt;/P&gt;

&lt;P&gt;Everything in the &lt;CODE&gt;main&lt;/CODE&gt; index came from either (1) inputs that you defined or (2) inputs defined by apps that you installed.&lt;/P&gt;

&lt;P&gt;If you are monitoring the Linux or Windows system where Splunk is running - which is probably what &lt;CODE&gt;SPLUNK01.My.Domain&lt;/CODE&gt; is - these are &lt;EM&gt;not&lt;/EM&gt; Splunk internal logs. These are just regular system logs. These logs could be indexed in the &lt;CODE&gt;main&lt;/CODE&gt; index or the &lt;CODE&gt;os&lt;/CODE&gt; index or whatever - but these logs &lt;EM&gt;do&lt;/EM&gt; count against your license. While it is a good idea to monitor the systems where Splunk is running, you can change or disable these inputs. Limiting these inputs &lt;STRONG&gt;will&lt;/STRONG&gt; decrease your Splunk license usage.&lt;/P&gt;

&lt;P&gt;People often install the Linux or Windows apps on their Splunk servers. This is most likely the origin of these inputs. If you have these apps, I suggest that you check the configurations.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2013 21:03:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108037#M22727</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-10-21T21:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK index main logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108038#M22728</link>
      <description>&lt;P&gt;Thank you!!!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2013 21:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-index-main-logs/m-p/108038#M22728</guid>
      <dc:creator>jviteka</dc:creator>
      <dc:date>2013-10-21T21:27:35Z</dc:date>
    </item>
  </channel>
</rss>

