<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 100% use of my events. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/100-use-of-my-events/m-p/462072#M79751</link>
    <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/admin/Limitsconf"&gt;https://docs.splunk.com/Documentation/Splunk/latest/admin/Limitsconf&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;you are asking two things.which do you want to know &lt;EM&gt;index&lt;/EM&gt; or &lt;EM&gt;search&lt;/EM&gt; ?&lt;/P&gt;</description>
    <pubDate>Sun, 24 May 2020 20:48:56 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-05-24T20:48:56Z</dc:date>
    <item>
      <title>100% use of my events.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/100-use-of-my-events/m-p/462071#M79750</link>
      <description>&lt;P&gt;Hello community.&lt;/P&gt;

&lt;P&gt;I have a query and I don't know if what I'm thinking can be achieved and how or if Splunk already has a way to solve my question.&lt;/P&gt;

&lt;P&gt;My question is:&lt;BR /&gt;
How to know how many bytes and fields extracted from my events in a particular index I am taking advantage of in searches?&lt;/P&gt;

&lt;P&gt;I would like to be able to identify if I am indexing more than what is really useful for my dashboards.&lt;/P&gt;</description>
      <pubDate>Sun, 24 May 2020 14:27:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/100-use-of-my-events/m-p/462071#M79750</guid>
      <dc:creator>lufermalgo</dc:creator>
      <dc:date>2020-05-24T14:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: 100% use of my events.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/100-use-of-my-events/m-p/462072#M79751</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/admin/Limitsconf"&gt;https://docs.splunk.com/Documentation/Splunk/latest/admin/Limitsconf&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;you are asking two things.which do you want to know &lt;EM&gt;index&lt;/EM&gt; or &lt;EM&gt;search&lt;/EM&gt; ?&lt;/P&gt;</description>
      <pubDate>Sun, 24 May 2020 20:48:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/100-use-of-my-events/m-p/462072#M79751</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-24T20:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: 100% use of my events.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/100-use-of-my-events/m-p/462073#M79752</link>
      <description>&lt;P&gt;Hi @lufermalgo,&lt;BR /&gt;
I think that the only way to understand if all the indexed logs (or which part of them) are useful for you is to analyze informations in your logs: fields, messages, etc...&lt;/P&gt;

&lt;P&gt;Analyzyng this, you can understand if there are events without useful informations and then exclude them before indexing using regexes.&lt;BR /&gt;
An example to understand: if you need to know only accesses to windows servers, you need only few EventCodes (4624, 4625, 4634, etc...) so you could exclude events e.g. with EventCode=4688 (A new process has been created).&lt;/P&gt;

&lt;P&gt;There are two methids to filter events: you can take only some interesting events and discard the others or discard only unuseful events and take all the other events.&lt;/P&gt;

&lt;P&gt;The way to filter events is described at &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 06:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/100-use-of-my-events/m-p/462073#M79752</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-05-25T06:31:32Z</dc:date>
    </item>
  </channel>
</rss>

