All Apps and Add-ons

Avoid installing demo data ?

yeastie65
New Member

Hi contributors, many thanks for that interesting app. Is it possible to install it without demo data ?

0 Karma

David
Splunk Employee
Splunk Employee

If you would like to, you can decompress the download and delete the demo data lookups.

The csvs that are required for app functionality are documented here: https://docs.splunksecurityessentials.com/technical-details/lookups/ (note that this includes CSV-based lookups, which is what we're concerned about here, along with kvstore collections that you don't need to worry about.

That said, remember that the demo data is just a series of CSV files that never get indexed, so they don't clog up your indexes or use any license, and by default this data isn't replicated to the indexers so it won't increase bundle sizes. There is no technical problem associated with installing this app (including the demo data) on a production system. This is the same for most of the essentials apps, notably excluding Splunk Security Essentials for Fraud which ships with many GB of demo data.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...