Splunk Search

Exclude unwanted apps from web-logs

AL3Z
Builder

Hi,

Can anyone pls figure out from these  list of apps which of these apps from web logs are not required for investigation/needed for ingesting in to Splunk to save the license cost ?
ssl
windows-remote-management
web-browsing
sap
ms-office365-base
google-base
soap
new-relic
okta
ms-onedrive-base
windows-push-notifications
dns-over-tls
crowdstrike
dns-over-https
outlook-web-online
ms-store
paloalto-updates
websocket
apple-push-notifications
gmail-base
yahoo-web-analytics
whatsapp-web
naver-line
hotmail
http-proxy
adobe-creative-cloud-base
telegram-base
ocsp
pan-db-cloud
windows-azure-base
github-base
apple-update
deepl-base
slack-base
egnyte-base
teamviewer-base
google-meet
facebook-chat
concur-base
google-docs-base
qlikview
paloalto-wildfire-cloud
successfactors
reddit-base
bananatag
google-analytics
as2
cisco-spark-base
viber-base
jabber
google-chat
taobao
appdynamics
icloud-mail
cloudinary-base
zoom-base
imgur-base
webdav
splashtop-remote
zscaler-internet-access
google-drive-web
ms-onedrive-business
liveperson
discord
salesforce-base
tokbox
quora-base
paloalto-dns-security
giphy-base
vimeo-base
giphy-downloading
notion-base
webex-base
openai-base
paloalto-cloud-identity
zendesk-base
paloalto-logging-service
dailymotion
paloalto-prisma-sdwan-control
paloalto-shared-services
cloudflare-warp
sharepoint-online
facebook-video

 

Thanks

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This is an almost impossible ask as it depends on what scenarios you want to investigate and which of these apps are and are not involved.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...