Modify Raw Events to Remove Fields and Reduce Storage
This video shows you how to remove unwanted fields from a raw event and reconstruct it with a reduced number of fields to optimize storage in the Splunk platform.
Related Videos
Access your data with Federated Analytics for Amazon Security Lake. Insights from Splunk, AWS, and Accenture.
Create a Splunk pipeline to filter, mask, and route logs - without SPL2
Splunk ARI Feature Video: Compliance Framework Mapping