All Apps and Add-ons

Can I choose what to index in Splunk?

satoshi86
Engager

Hello to all Splunk wizards,

I would like to know if it is possible for me to choose what data to index in Splunk. The reason behind it is to limit the license usage of the Splunk server.

I currently owned a 2GB licensed daily volume, but once I've started monitoring the Fortigate firewall (syslog enabled), it consumes the license's quota till it reaches a violation.

What I'm thinking of doing is to only index the "status = deny" in order to limit the licensed daily volume.

Thanks.

0 Karma
1 Solution

satoshi86
Engager

sriousx : It seems that my vendor is not experienced enough to control the severity level on the firewall. But I thank you for your input.

0 Karma

satoshi86
Engager

Thanks alot Ayn!!

0 Karma

srioux
Communicator

Can also change logging level on the originating box itself. We do this on a number of network devices (primarily Cisco), and it works just fine.

Vendor docs should have some portion on how to control syslog verbosity.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...