Modify Raw Events to Remove Fields and Reduce Storage
This video shows you how to remove unwanted fields from a raw event and reconstruct it with a reduced number of fields to optimize storage in the Splunk platform.
Related Videos
Classify and Compress Palo Alto Logs with Splunk Data Management
Optimize Cisco ASA Logs with Splunk Ingest Processor Templates