Getting Data In

How do I stop indexer automatically if I reached my data limit?

jangid
Builder

How Do I stop indexer if I reached my daily data limit?

Tags (3)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

There is nothing in Spunk to do that automatically. I suppose you could create an alert to monitor the amount of indexed data for a given day. You'll find several examples on Splunkbase. Then have the alert kick off a script to do whatever you want.

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

There is nothing in Spunk to do that automatically. I suppose you could create an alert to monitor the amount of indexed data for a given day. You'll find several examples on Splunkbase. Then have the alert kick off a script to do whatever you want.

Get Updates on the Splunk Community!

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through: An introduction to the Splunk Threat ...