<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk license usage question in Security</title>
    <link>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350258#M12457</link>
    <description>&lt;P&gt;Hi @ananthan123 - Please accept the best answer so your question will be marked as resolved. But you can up-vote the other answers as well, that way these users will know you're appreciative of their help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Thanks and Happy Splunking!&lt;/P&gt;</description>
    <pubDate>Thu, 03 Aug 2017 16:09:29 GMT</pubDate>
    <dc:creator>aaraneta_splunk</dc:creator>
    <dc:date>2017-08-03T16:09:29Z</dc:date>
    <item>
      <title>splunk license usage question</title>
      <link>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350253#M12452</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I  have a question about forwarder and log indexing.&lt;/P&gt;

&lt;P&gt;How often forwarder pushes the data to Indexer? How do I modify the time?&lt;/P&gt;

&lt;P&gt;How do I know what are the events and logs are taking affect on licence usage?&lt;/P&gt;

&lt;P&gt;Are these  splunk log files push to indexer? And does it affect on licence usage?&lt;BR /&gt;
$ sudo  ls /opt/splunk/var/log/splunk&lt;BR /&gt;
audit.log           first_install.log  metrics.log.5        splunkd_stderr.log&lt;BR /&gt;
btool.log           license_usage.log  mongod.log           splunkd_stdout.log&lt;BR /&gt;
conf.log            metrics.log        remote_searches.log  splunkd_ui_access.log&lt;BR /&gt;
django_access.log   metrics.log.1      scheduler.log        splunkd-utility.log&lt;BR /&gt;
django_error.log    metrics.log.2      searchhistory.log    web_access.log&lt;BR /&gt;
django_service.log  metrics.log.3      splunkd_access.log   web_service.log&lt;BR /&gt;
export_metrics.log  metrics.log.4      splunkd.log&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:13:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350253#M12452</guid>
      <dc:creator>ananthan123</dc:creator>
      <dc:date>2020-09-29T15:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: splunk license usage question</title>
      <link>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350254#M12453</link>
      <description>&lt;P&gt;hello there,&lt;BR /&gt;
everything that is being indexed in internal indexes, meaning indexes that starts with an "_" (underscore) will not count against your license.&lt;BR /&gt;
everything that is on the forwarder /var/log/splunk/ will not count against your license as default monitor for it is to go to internal indexes.&lt;BR /&gt;
forwarder will tail files and send them to splunk. if you are using "monitor" for inputs, there is no interval set. when new line is added to the monitored file, the forwarder reads it and sends it to indexer.&lt;BR /&gt;
hope it helps&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 14:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350254#M12453</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-08-03T14:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: splunk license usage question</title>
      <link>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350255#M12454</link>
      <description>&lt;P&gt;The log files in &lt;CODE&gt;index=_internal&lt;/CODE&gt; do not count against your license quota. See &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Troubleshooting/WhatSplunklogsaboutitself"&gt;What Splunk software logs about itself&lt;/A&gt; in the &lt;EM&gt;Troubleshooting Manual&lt;/EM&gt; for more information about Splunk platform logging.&lt;/P&gt;

&lt;P&gt;For all practical purposes, the forwarder works continuously. There are some attributes related to timeout intervals and load balancing that you can set in the &lt;CODE&gt;outputs.conf&lt;/CODE&gt;file. See &lt;A href="http://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Configureforwardingwithoutputs.conf"&gt;Configure forwarding with outputs.conf&lt;/A&gt; in the &lt;EM&gt;Forwarder Manual&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 14:49:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350255#M12454</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2017-08-03T14:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: splunk license usage question</title>
      <link>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350256#M12455</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
answering to your question:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;by default 30 seconds, you can modify it changing the autoLBFrequency parameter in forwarder's outputs.conf (see &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/outputsconf?r=searchtip"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/outputsconf?r=searchtip&lt;/A&gt;), &lt;/LI&gt;
&lt;LI&gt;all indexed logs affect license usage, it's possible to filter data before indexing (see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/Forwarding/Routeandfilterdatad&lt;/A&gt;) and the filtered logs doesn't affect license.&lt;/LI&gt;
&lt;LI&gt;Internal Splunk logs don't affect license.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 15:19:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350256#M12455</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-03T15:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunk license usage question</title>
      <link>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350257#M12456</link>
      <description>&lt;P&gt;thank you for all of  you.  I would like to accept all of your answers. Can I accept all or need to accept one?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 16:05:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350257#M12456</guid>
      <dc:creator>ananthan123</dc:creator>
      <dc:date>2017-08-03T16:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: splunk license usage question</title>
      <link>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350258#M12457</link>
      <description>&lt;P&gt;Hi @ananthan123 - Please accept the best answer so your question will be marked as resolved. But you can up-vote the other answers as well, that way these users will know you're appreciative of their help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Thanks and Happy Splunking!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 16:09:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-license-usage-question/m-p/350258#M12457</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2017-08-03T16:09:29Z</dc:date>
    </item>
  </channel>
</rss>

