Hi Giuseppe, yes I understand how Splunk stores its data in the indexes. But when I run the scripted input every hour, it creates 24 entries for one device entry from the target system. But with Scripted Input I'm not just getting one entry back, I could be getting 200 entries back from the target system. And then 24 entries a day for 200 device entries is a lot, over a long period of time it takes a lot of space on the indexer. So I want to find a way to store the data from the scripted input on the indexer, but not store too many duplicates of the same device entries. FYI: With the Script for the Scripted Input I ask the API of an i-doit System, which is a Software for IT-Documentation to give me all of its stored device-entries. Thanks in advance.
... View more