<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to limit  the amount  of data that a splunk  universal  forwarder  sends to the Splunk  server  for processing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249710#M48061</link>
    <description>&lt;P&gt;Thank you realsplunk, that document will be useful! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Aug 2016 16:55:20 GMT</pubDate>
    <dc:creator>vvmmvvmm</dc:creator>
    <dc:date>2016-08-25T16:55:20Z</dc:date>
    <item>
      <title>How to limit  the amount  of data that a splunk  universal  forwarder  sends to the Splunk  server  for processing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249706#M48057</link>
      <description>&lt;P&gt;Hi there &lt;/P&gt;

&lt;P&gt;I am using Splunk Enterprise for security purposes...&lt;/P&gt;

&lt;P&gt;But ther is a lot of extraneous data in my Splunk at the moment. Looking  through the dashboards I am finding a lot  of performance and operational  status data which I don't need. The problem is that my splunk  license allows me to  analyze 2gb of data in  a 24 hour period. I  would say that at the moment  70% of the data that  goes through the system  is not  security  related and the system was procured as a security  monitoring  system.&lt;/P&gt;

&lt;P&gt;I would like to  find a way  to  reduce the mount  of the data that the "forwarders" send back to the Splunk  back end for processing. i.e. exclude all of the performance and operational data from the analysis.&lt;/P&gt;

&lt;P&gt;My intention is to use that  freed up  bandwidth  to  push some Anti Virus and Firewall  logs to splunk instead of server  performance data. &lt;/P&gt;

&lt;P&gt;I would really really appreciate some help with this. I have searched previous questions, but can't seem to find the answer. However, if there is a page you know of where I can find my answer please send me the link &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;

&lt;P&gt;Kind Regards&lt;/P&gt;

&lt;P&gt;Vera&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 10:14:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249706#M48057</guid>
      <dc:creator>vvmmvvmm</dc:creator>
      <dc:date>2016-08-25T10:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit  the amount  of data that a splunk  universal  forwarder  sends to the Splunk  server  for processing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249707#M48058</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;You just need to disable the inputs that you dont need, and you will stop receiving that data.&lt;/P&gt;

&lt;P&gt;If in the same source, there is performance and security data mixed, then you can use the null queue to avoid indexing the events that matches the patterns you define.&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 14:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249707#M48058</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2016-08-25T14:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit  the amount  of data that a splunk  universal  forwarder  sends to the Splunk  server  for processing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249708#M48059</link>
      <description>&lt;P&gt;Hello, look at &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.1/Forwarding/Routeandfilterdatad&lt;/A&gt; : "Filter event data and send to queues"&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 14:42:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249708#M48059</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2016-08-25T14:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit  the amount  of data that a splunk  universal  forwarder  sends to the Splunk  server  for processing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249709#M48060</link>
      <description>&lt;P&gt;Thank you so much, appreciate your help! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 16:54:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249709#M48060</guid>
      <dc:creator>vvmmvvmm</dc:creator>
      <dc:date>2016-08-25T16:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit  the amount  of data that a splunk  universal  forwarder  sends to the Splunk  server  for processing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249710#M48061</link>
      <description>&lt;P&gt;Thank you realsplunk, that document will be useful! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 16:55:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-the-amount-of-data-that-a-splunk-universal/m-p/249710#M48061</guid>
      <dc:creator>vvmmvvmm</dc:creator>
      <dc:date>2016-08-25T16:55:20Z</dc:date>
    </item>
  </channel>
</rss>

