Hello. I cannot find an answer to this simple question, although I have found other information utilizing props.conf and transforms in more complicated situations. I currently have a single Splunk instance as an all-in-one solution, and I am looking for a simple method to truncate ISE logs to 2000 characters to lower Splunk database size. ISE itself is not capable of this. I am very familiar with Splunk via GUI, but not at all with modifying the configuration files, so step by step instructions would be very helpful. Thanks in advance.
... View more