All Apps and Add-ons

How to safely delete syslog messages after indexing?

bayman
Path Finder

I have the Cisco ASA Firewall device sending syslog messages to tcp/udp port 5514 on the Splunk server. These syslog messages are taking up over 100gb on /var/log and they are also getting indexed in $SPLUNK_DB/cisco_asa/db with a max index size of 50gb for the Splunk_CiscoSecuritySuite app on the same Splunk server. How can I safely delete the /var/log messages without affecting the cisco_asa index?

0 Karma

aakwah
Builder

As per the mentioned setup if Splunk is listening on port 5514 there should be nothing in /var/log related to syslog steam coming from Cisco firewall, all received logs will be stored in Splunk index at this location $SPLUNK_DB/cisco_asa/db

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...