My Splunk Enterprise is running for a few months.
I'm sending all my logs (HEC and UDP) to index "main".
However, I see some indexes defined, mainly I'm concerned about the top-consuming ones: `_audit`, `_internal` and `_introspection`.
![indexes][1]
What processes are sending data to them? What value is that for me? Is it consuming my license quota? And where can I configure/disable these?
Thanks
[1]: https://i.imgur.com/UUBJFf2.png
↧