Deployment Architecture

Stop data flowing into 1 of my Indexes

rdelmark
Explorer

Is there a quick way to stop all data flowing into one of my indexes on a temp basis.

I have a windowsec index that is recieving 25GB per day, at this time I don't need the data, I would like to be able to quickly stop that data flowing in so that I can save this license cost but quickly restart the data flow again when the requirement exists in a few months.

Tags (3)
0 Karma

ChrisG
Splunk Employee
Splunk Employee

There are instructions in the Forwarding Data manual that explain how to filter data by target index.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...