After I configured the product to send events to Splunk using the SIEM action, I noticed that the Journal data set fills up quickly. What can I do to resolve this issue?