I need to create an alert but the data to be fetched from the server is using a lot of license in Splunk.
The data that has to be fetch are few keywords from a excel file that will be available on the server. I need to install Universal Forwarder on the servers . Is it possible to make any changes at Universal forwarder level so that it can forward only the Keywords to Splunk? If not what alternative option there is to ingest the data without it using a lot of Splunk license?
Hi @chaturvedi ,
if you're speking of Windows logs, you can select the whitelists and blacklists to choose the data to index.
You can find more infos at https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/Inputsconf
otherwise, you have to follow the instructions at https://docs.splunk.com/Documentation/Splunk/9.3.0/Forwarding/Routeandfilterdatad
Ciao.
Giuseppe