Splunk Enterprise

How to reduce quota size?

jip31
Motivator

Hello

I use a very basic search on a short period like below but  I am a little surprised by the quota size used by this search (350 MO for 148000 events between 7h and 13h) 

 

index=tutu sourcetype="toto" type=x earliest=@d+7h latest=@d+19h 
| fields sam 
| eval sam=lower(s) 
| stats dc(s)

 

 So I try to find some tracks for reducing the quota size

Is anybody have an idea please?

Tags (1)
0 Karma

effem2
Path Finder

What sizes are all other Searchresults usually? Take a look at the Job Activity.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...