Hi @alaa_ahmad, as I said, it's possible to filter data before indexing to reduce the license consuption, but in this way you cannot use the discarded events (or part of them). If in your events there's a redendant part of the event that can be discarded, you have to find a regex to identify the relevant part to maintain or the not relevant part to remove. If you cannot, the only way is a larger license. As I said, if you want to remove the entire event you can follow the procedure described at https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues taking only the relavant data and discardinf the others or discarding a part of events. If instead you want to reduce the events, you can follow the anonymization procedure I described in the above message. In all these solutions, you have to identify one or more regexes to identify the the part of events to maintain or to discard. Ciao. Giuseppe
... View more