Hi,
I'm evaluating Splunk Enterprise for servers and PCs access logs archiving; as far as I can see Splunk creates its own access logs on machines but I won't archive them.
How prevent splunk from collecting its own access logs on servers and PCs?
@katiasolmi Splunk's _internal logs do not charge against License. Is there any other reason for Stopping Splunk's _internal logs?
[Update]
Adding documentation: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations
Internal indexes (for example,
_internal and _introspection) do not count against your license volume.
It was just for license. Are you sure they're not charged for daily MB limit?
yes, they are definitely not part of license usage