Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Can I blacklist sourcetype or Index?

$
0
0
We have client logs getting indexed using RestAPI and our license is overloaded with high volume. Because of restapi setup we don't have forwarder pushing logs to Splunk indexer-- its getting indexed directly from user machines. Is there any way we can just blacklist the index or source type? Thanks

Viewing all articles
Browse latest Browse all 47296


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>