I started mucking around with Splunk at home since I was going to be responsible for it at work and I kinda like it so I setup a single instance at the house to monitor my network traffic. Most things are fine but for some reason for a couple of days, it went bonkers to the tune of >4GB! WOW.
I get Splunk not wanting people to use it for free when they have really big - even lab -networks but I have like 5 or 6 vms and a couple of Pis. The issue is that I can't do any searches to see who is sending the data so that I can stop it. Is there a simple way to reset the number of exceeds so that I can troubleshoot what's sending all the data and turn it off?
... View more