Hi Everyone,
I want to install splunk trail version. I have multiple Domain Controllers, File Servers, Exchange Server, Firewalls.
the idea is to present splunk capabilities.
Please tell me:
1-Trial license is 500 MB/per day so what should be my strategy( how many indexers, search heads and Forwarders I can configure)
2- estimate space required for each data source, for example, for DC how many events can be indexed.
3- what should be my architecture strategy.
4- How can I drop windows events at universal forwarder or Index level.
5- How can I filter network events( should I do this at network device it self .. OR i can drop events at index level.
... View more