We are in the process of combining two Splunk instances. We have data we want to start transitioning from one Splunk to another, but we are hitting license capacity. We are still pending getting a contract for additional capacity. Is there a way to throttle data on the forwarders without having to reduce data sources in general? Some of the data is already being throttle at the source if it can, but some of it cannot. Thank you.
↧