Splunk Enterprise

SPLUNK Forwarders: is there a way to forward types of files in one folder selectively?

lbraginsky
New Member

Hello,

I'm trying to limit the amount of data that SPLUNK indexes daily and I noticed that a bunch of our server log files contain lots of reduntant data and hence can be skipped. HOWEVER, the "useless" files live in the same folders as some of the "useful" files. Question: is there a way to segregate files that Forwarders pick up from the same directory (we have both Windows and Linux servers)?

Thanks,

leo

Tags (1)
0 Karma

Ayn
Legend

Sure. Check out the whitelisting/blacklisting mechanisms in inputs.conf.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...