All Apps and Add-ons

Splunk App for VMware - Licence

abdulhasnath
New Member

Hi, I have installed this app and configured it using the addon. I was able to see the data, however, I am exceeding the trial licence daily limit of 2GB. Currently, I have 5GB data coming in, as a result, I cannot view anything. Can you please advise how I can reduce what is coming in from the addon? So that I can use the app and experiment if it is suitable for our needs?
Thanks
Abdul

0 Karma

MoniM
Communicator

Hi @abdulhasnath ,
If you want to limit your data, you can configure props.conf and transforms.conf. You can discard unwanted data by routing it to nullQueue.
NOTE- When you filter out data in this way, the filtered data is not forwarded or added to the index at all, and doesn't count toward your indexing volume.

For detail information, you can follow the documentation here https://docs.splunk.com/Documentation/Splunk/6.0.3/Forwarding/Routeandfilterdatad#Filter_event_data_...

Hope it helps!!
Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...