Getting Data In

Data to be ingested in splunk is consuming a lot of splunk license

chaturvedi
New Member

I need to create an alert but the data to be fetched from the server is using a lot of license in Splunk.
The data that has to be fetch are few keywords from a excel file that will  be available on the server. I need to install Universal Forwarder on the servers . Is it possible to make any changes at Universal forwarder level so that it can forward only the Keywords to Splunk? If not what alternative option there is to ingest the data without it using a lot of Splunk license?

 

 

Labels (4)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @chaturvedi ,

if you're speking of Windows logs, you can select the whitelists and blacklists to choose the data to index.

You can find more infos at https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/Inputsconf 

otherwise, you have to follow the instructions at https://docs.splunk.com/Documentation/Splunk/9.3.0/Forwarding/Routeandfilterdatad

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...