Hi ,
I would like to know, is there any way to stop the indexing if any specific source file grows 1 GB in size. Sometimes our logs growing very fast and it is affecting daily license usage limit in splunk. So we are planning to stop the files which is growing more than 1 GB. Please help me here?
Thanks!
A creative method :
index=_internal source=*license_usage.log type=Usage st="yoursourcetype"
| stats sum(b) AS bytes by st
| eval MB= round(bytes/1024/1024,1)
| where MB>1000
| fields st MB
Hi,
Thanks for your reply, I am not sure how to get that script which get the config file and disable source. can you please help me on that? By that script are we going to disable the source or sourcetype? if it is source then it will disable which source?
Everything that you can do from the GUI can be done with a CLI command using this:
$SPLUNK_HOME/bin/splunk edit monitor MyStanzaHeaderHere -disabled true
Hi ,
Thanks, let me try and update you.