All Apps and Add-ons

Splunk App for VMware - Licence

abdulhasnath
New Member

Hi, I have installed this app and configured it using the addon. I was able to see the data, however, I am exceeding the trial licence daily limit of 2GB. Currently, I have 5GB data coming in, as a result, I cannot view anything. Can you please advise how I can reduce what is coming in from the addon? So that I can use the app and experiment if it is suitable for our needs?
Thanks
Abdul

0 Karma

MoniM
Communicator

Hi @abdulhasnath ,
If you want to limit your data, you can configure props.conf and transforms.conf. You can discard unwanted data by routing it to nullQueue.
NOTE- When you filter out data in this way, the filtered data is not forwarded or added to the index at all, and doesn't count toward your indexing volume.

For detail information, you can follow the documentation here https://docs.splunk.com/Documentation/Splunk/6.0.3/Forwarding/Routeandfilterdatad#Filter_event_data_...

Hope it helps!!
Thanks

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...