There are logs which I want to index, search and create alerts for. But some logs are only required for a detailed analysis, which happens less than once a month. However, those logs would only push me over the license quota.
I therefore do intend to use Splunk, but I want to avoid using another software to collect and manage other logs.
The Splunk WBT specifically mentions that parsing logs does not affect the license, only indexing. So far I have not been able to figure out how to parse without indexing.
... View more