Hello, I have same kind of issue in the environment.. could you please elaborate in detail on how to identify which logs are useful and which can be omitted from using the splunk license. We have created a custom index that ingests the auditd logs from all the splunk enterprise instances only which includes all HFs, SHs, and Indexer components. We had disabled the inputs as a workaround as it was breaching our license capacity. Regards
... View more