Installation

sed cmd and indexing volume count

cafissimo
Communicator

Hello, I would like to know something about SEDCMD command. If I eliminate a portion of my record, what does it count for license? The original event or only the portion of the event that I am keeping?

Here is an example of my sedcmd command

[source::.../accounts.log]
SEDCMD-foobar = s/foobar//g

Thanks in advance and kind regards.

Luca Caldiero

Tags (3)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Only the indexed portion will count for license, i.e., any content that you delete using SEDCMD will not be counted.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Only the indexed portion will count for license, i.e., any content that you delete using SEDCMD will not be counted.

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...