Modify Raw Events to Remove Fields and Reduce Storage
This video shows you how to remove unwanted fields from a raw event and reconstruct it with a reduced number of fields to optimize storage in the Splunk platform.
Related Videos
Splunk Enterprise Security 8.0 Comprehensive Demo - The Market-Leading SIEM for the SOC of the Future
SOAR in Seconds - Playbook Building with Natively Integrated SIEM and SOAR