<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to filter a large amount of index data being generated by the head index server? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314293#M58827</link>
    <description>&lt;P&gt;applied on indexer (that's all there is). service was restarted&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2018 16:46:34 GMT</pubDate>
    <dc:creator>ntripp_element</dc:creator>
    <dc:date>2018-02-27T16:46:34Z</dc:date>
    <item>
      <title>How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314291#M58825</link>
      <description>&lt;P&gt;I've noticed the head index server is generating an absurd amount of index data and I want to filter it out&lt;/P&gt;

&lt;P&gt;I have a stanza in props:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[host::&amp;lt;hostname&amp;gt;]
 TRANSFORMS-&amp;lt;hostname&amp;gt; = host_setnull
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[host_setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is there something else I'm missing? I'm still seeing the events increment.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 16:34:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314291#M58825</guid>
      <dc:creator>ntripp_element</dc:creator>
      <dc:date>2018-02-27T16:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314292#M58826</link>
      <description>&lt;P&gt;Where did you apply these changes? It should be done on your heavy/intermediate forwarder OR on indexer, whichever comes first in the data flow. A splunk restart is also required after making the change. &lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 16:42:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314292#M58826</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-02-27T16:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314293#M58827</link>
      <description>&lt;P&gt;applied on indexer (that's all there is). service was restarted&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 16:46:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314293#M58827</guid>
      <dc:creator>ntripp_element</dc:creator>
      <dc:date>2018-02-27T16:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314294#M58828</link>
      <description>&lt;P&gt;Does the &lt;CODE&gt;&amp;lt;host_name&amp;gt;&lt;/CODE&gt; you put in props.conf matches correctly with host field in the event? Is the head index server a server with forwarder installed on it? What's your environment looks like (topology wise)?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 17:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314294#M58828</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-02-27T17:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314295#M58829</link>
      <description>&lt;P&gt;is just a placeholder for the actual hostname that i put in the conf file. We have 1 splunk instance that we are feeding everything to and DCN node for the vmware stuff. So topology wise couldn't be much simpler.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 18:17:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314295#M58829</guid>
      <dc:creator>ntripp_element</dc:creator>
      <dc:date>2018-02-27T18:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314296#M58830</link>
      <description>&lt;P&gt;I'll take that as this should be working then?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 20:03:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314296#M58830</guid>
      <dc:creator>ntripp_element</dc:creator>
      <dc:date>2018-02-27T20:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314297#M58831</link>
      <description>&lt;P&gt;Looks good to me. So this head index server you're referring to, is it your Splunk indexer OR a server which is feeding data to your indexer?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 20:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314297#M58831</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-02-27T20:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314298#M58832</link>
      <description>&lt;P&gt;It's my Spunk indexer&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 21:29:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314298#M58832</guid>
      <dc:creator>ntripp_element</dc:creator>
      <dc:date>2018-02-27T21:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314299#M58833</link>
      <description>&lt;P&gt;So when you say it's generating absurd amount of indexed data, from where that data is coming from? Is being monitored/generated on your indexer server itself?  What sourcetype(s) does that unwanted data of your have?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 21:33:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314299#M58833</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-02-27T21:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314300#M58834</link>
      <description>&lt;P&gt;I thought it must be data from the indexer itself? We're on a trial and hit 100GB today I'm just trying to sort this by the largest volume events that I don't care about and trim this usage into something useful&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 21:37:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314300#M58834</guid>
      <dc:creator>ntripp_element</dc:creator>
      <dc:date>2018-02-27T21:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter a large amount of index data being generated by the head index server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314301#M58835</link>
      <description>&lt;P&gt;I would say you find out which sourcetype or sourcetypes are eating most of your license and then use your nullQueue routing for them. Try running this &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd component=LicenseUsage type=Usage | stats sum(b) as usage by st | sort 5 -usage | eval usage=round(usage/1024/1024/1024,2)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will give top 5 sourcetypes based on license usage for selected time range. From this list whatever sourcetypes that you don't want data to be ingested, you can either turn off the monitoring for it (it must be in inputs.conf somewhere) or apply TRANSFORMS for those sourcetypes.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 21:48:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-a-large-amount-of-index-data-being-generated-by/m-p/314301#M58835</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-02-27T21:48:49Z</dc:date>
    </item>
  </channel>
</rss>

