The indexes required by this app are using over 200GB of our Splunk license a day. I don't believe this to be normal behavior. This was from a fresh install and I verified the checkpoints from the online doc are valid (below). The only difference from the online doc and what I see in my configs from a fresh install is my app is missing "[isight_indicators]" and has "[isight_vulnerability]" - Page 15-16 Anyone else run into this issue before as well?
Referenced online doc: link text
[isight_iocs]
history_exec = 1544400000
last_exec = 1554375748
[isight_vulnerability]
history_exec = 1544400000
last_exec = 1554407948