<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I get a complete size of all logs ingested by Splunk Enterprise &amp;amp; Enterprise Security incl. Indexes in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/How-do-I-get-a-complete-size-of-all-logs-ingested-by-Splunk/m-p/549943#M9047</link>
    <description>&lt;P&gt;The first Best Practice is to only ingest what you need.&amp;nbsp; Disable inputs for use cases you're not monitoring.&amp;nbsp; Increase the input interval where possible.&amp;nbsp; Be picky about which Windows events you ingest.&lt;/P&gt;&lt;P&gt;Trim the fat from Windows events.&amp;nbsp; They all contain the same boiler-plate text at the end that serves no useful purpose.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.1.2101/Data/MonitorWindowseventlogdata#Suppress_fields_from_Windows_Event_Log_events" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.1.2101/Data/MonitorWindowseventlogdata#Suppress_fields_from_Windows_Event_Log_events&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-truncation-at-IDX-and-HF/m-p/442933" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-truncation-at-IDX-and-HF/m-p/442933&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Apr 2021 00:29:53 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-04-30T00:29:53Z</dc:date>
    <item>
      <title>How do I get a complete size of all logs ingested by Splunk Enterprise &amp; Enterprise Security incl. Indexes</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-I-get-a-complete-size-of-all-logs-ingested-by-Splunk/m-p/549845#M9032</link>
      <description>&lt;P&gt;How do I get a complete size of all logs ingested by Splunk Enterprise &amp;amp; Enterprise Security incl. Indexes. Showing indexes taking the most load?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 14:01:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-I-get-a-complete-size-of-all-logs-ingested-by-Splunk/m-p/549845#M9032</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-04-29T14:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get a complete size of all logs ingested by Splunk Enterprise &amp; Enterprise Security incl. Indexes</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-I-get-a-complete-size-of-all-logs-ingested-by-Splunk/m-p/549892#M9040</link>
      <description>&lt;P&gt;The Monitoring Console can show which indexes are getting the most data.&amp;nbsp; It will even break it out by source, sourcetype, and (IIRC) host.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 19:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-I-get-a-complete-size-of-all-logs-ingested-by-Splunk/m-p/549892#M9040</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-29T19:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get a complete size of all logs ingested by Splunk Enterprise &amp; Enterprise Security incl. Indexes</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-I-get-a-complete-size-of-all-logs-ingested-by-Splunk/m-p/549898#M9041</link>
      <description>&lt;P&gt;Thank u again Rich. Does the sizes show are the complete ( including all logs) for the Indexes. Are there any other place I need to check to come up with complete metrics? I am doing this for sake of saving licenses going over the limit. Would you by any chance have " best practices" for trimming the license fat ? Thank u sir.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 19:45:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-I-get-a-complete-size-of-all-logs-ingested-by-Splunk/m-p/549898#M9041</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-04-29T19:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get a complete size of all logs ingested by Splunk Enterprise &amp; Enterprise Security incl. Indexes</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-I-get-a-complete-size-of-all-logs-ingested-by-Splunk/m-p/549943#M9047</link>
      <description>&lt;P&gt;The first Best Practice is to only ingest what you need.&amp;nbsp; Disable inputs for use cases you're not monitoring.&amp;nbsp; Increase the input interval where possible.&amp;nbsp; Be picky about which Windows events you ingest.&lt;/P&gt;&lt;P&gt;Trim the fat from Windows events.&amp;nbsp; They all contain the same boiler-plate text at the end that serves no useful purpose.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.1.2101/Data/MonitorWindowseventlogdata#Suppress_fields_from_Windows_Event_Log_events" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.1.2101/Data/MonitorWindowseventlogdata#Suppress_fields_from_Windows_Event_Log_events&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-truncation-at-IDX-and-HF/m-p/442933" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-truncation-at-IDX-and-HF/m-p/442933&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 00:29:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-I-get-a-complete-size-of-all-logs-ingested-by-Splunk/m-p/549943#M9047</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-30T00:29:53Z</dc:date>
    </item>
  </channel>
</rss>

