Splunk Dev

Prevent splunk from collecting its own access logs on servers and PCs

katiasolmi
New Member

Hi,
I'm evaluating Splunk Enterprise for servers and PCs access logs archiving; as far as I can see Splunk creates its own access logs on machines but I won't archive them.

How prevent splunk from collecting its own access logs on servers and PCs?

Tags (1)
0 Karma

niketn
Legend

@katiasolmi Splunk's _internal logs do not charge against License. Is there any other reason for Stopping Splunk's _internal logs?

[Update]
Adding documentation: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutlicenseviolations

Internal indexes (for example,
_internal and _introspection) do not count against your license volume.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

katiasolmi
New Member

It was just for license. Are you sure they're not charged for daily MB limit?

0 Karma

WalshyB
Path Finder

yes, they are definitely not part of license usage

0 Karma
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...