Getting Data In

Splunk Routing to Non-Indexing Queue

DanMelar
New Member

Within Splunk, is there a way to route data to a queue that doesn't index. If so, could you turn on the ability to index that data if needed? I have a large amount of data coming in (100+GB Per Day) but have a very small license. Can this routing be done via the Splunk Server and not with a heavy forwarder?

Tags (2)
0 Karma

DanMelar
New Member

I would not like to 'drop' the events, rather keep them and not index them.

0 Karma

yannK
Splunk Employee
Splunk Employee

Do not route to a non existing queue, it will simply block your indexer once full.

But you can route to the nullQueue to drop events.
http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Routeandfilterdatad#Discard_specific_events...

0 Karma

DanMelar
New Member

I would not like to 'drop' the events, rather keep them and not index them.

0 Karma

bmacias84
Champion
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...