Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Can I blacklist sourcetype or Index?

$
0
0
We have client logs getting indexed using RestAPI and our license is overloaded with high volume. Because of restapi setup we don't have forwarder pushing logs to Splunk indexer-- its getting indexed directly from user machines. Is there any way we can just blacklist the index or source type? Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>