<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic when a setup a blacklist in input.conf, will it decrease the usage of license? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/when-a-setup-a-blacklist-in-input-conf-will-it-decrease-the/m-p/473030#M87696</link>
    <description>&lt;P&gt;As I asked, if I setup a blacklist to deny some logs, does the dropped logs still occupy the license quota?&lt;/P&gt;</description>
    <pubDate>Mon, 17 Feb 2020 09:31:37 GMT</pubDate>
    <dc:creator>lllidan</dc:creator>
    <dc:date>2020-02-17T09:31:37Z</dc:date>
    <item>
      <title>when a setup a blacklist in input.conf, will it decrease the usage of license?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/when-a-setup-a-blacklist-in-input-conf-will-it-decrease-the/m-p/473030#M87696</link>
      <description>&lt;P&gt;As I asked, if I setup a blacklist to deny some logs, does the dropped logs still occupy the license quota?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 09:31:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/when-a-setup-a-blacklist-in-input-conf-will-it-decrease-the/m-p/473030#M87696</guid>
      <dc:creator>lllidan</dc:creator>
      <dc:date>2020-02-17T09:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: when a setup a blacklist in input.conf, will it decrease the usage of license?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/when-a-setup-a-blacklist-in-input-conf-will-it-decrease-the/m-p/473031#M87697</link>
      <description>&lt;P&gt;Hi @lllidan,&lt;BR /&gt;
Splunk License is counted on dayly indexed logs, this means that all the logs that you don't index (e.g. filtering) aren't added to the license consuption, but they are also non useful!&lt;BR /&gt;
Blacklisting some logs, you don't index them so you don't use license.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 09:36:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/when-a-setup-a-blacklist-in-input-conf-will-it-decrease-the/m-p/473031#M87697</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-02-17T09:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: when a setup a blacklist in input.conf, will it decrease the usage of license?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/when-a-setup-a-blacklist-in-input-conf-will-it-decrease-the/m-p/473032#M87698</link>
      <description>&lt;P&gt;thanks a lot.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 09:42:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/when-a-setup-a-blacklist-in-input-conf-will-it-decrease-the/m-p/473032#M87698</guid>
      <dc:creator>lllidan</dc:creator>
      <dc:date>2020-02-17T09:42:04Z</dc:date>
    </item>
  </channel>
</rss>

