All,
One of our application is generating lot of logs and which cause the splunk to exceed daily indexing limit.
I want to limit the indexing size of that indexer alone on per day basis. please help me to find a way.
We are using splunk 6.0 is a distributed one with 2 indexers,2 search head a deployment client and 40+ forwarders.
Thanks in advance.
See the Accepted answer-> Update in below link.
http://answers.splunk.com/answers/133512/how-to-limit-the-maximum-daily-indexing-volume