Archive

Prevent splunk from collecting its own access logs on servers and PCs

katiasolmi
New Member

Hi,
I'm evaluating Splunk Enterprise for servers and PCs access logs archiving; as far as I can see Splunk creates its own access logs on machines but I won't archive them.

How prevent splunk from collecting its own access logs on servers and PCs?

Tags (1)
0 Karma

niketnilay
Legend

@katiasolmi Splunk's _internal logs do not charge against License. Is there any other reason for Stopping Splunk's _internal logs?

[Update]
Adding documentation: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

Internal indexes (for example,
_internal and _introspection) do not count against your license volume.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

katiasolmi
New Member

It was just for license. Are you sure they're not charged for daily MB limit?

0 Karma

WalshyB
Path Finder

yes, they are definitely not part of license usage

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.