Getting Data In

bar logs with debug level enabled

bmcaetano
Engager

Is there any way to block logs coming from other servers, on a distributed server, with the debug level activated? I say this because our splunk is suffering performance degradation due to the amount of DEBUG logs. I'm still studying the props.conf documentation, would this be the right way to do this?

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Take a look at Ingest Actions

bowesmana_0-1707099276364.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

another option is use those props.conf and transforms.conf files as you already have looked. Here is one old post to do it https://community.splunk.com/t5/Monitoring-Splunk/FortiGate-Firewall-is-consuming-the-license/m-p/64... There are lot of other examples in community and also on docs.splunk.com. 

One thing what you must remember is that you must put those configurations on 1st full splunk instance from source to indexers. This could be a HF or an indexer.

r. Ismo

 

0 Karma
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...