<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index Volume, Licence Use Question in Security</title>
    <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121914#M14441</link>
    <description>&lt;P&gt;You could give them access to &lt;CODE&gt;_internal&lt;/CODE&gt; but restrict that to metrics about their index.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Apr 2014 13:08:34 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2014-04-07T13:08:34Z</dc:date>
    <item>
      <title>Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121909#M14436</link>
      <description>&lt;P&gt;I am using this search to find volume for systems reporting to one index&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index="_internal" source="*metrics.log" per_index_thruput series="Customer_Index_group" | stats sum(kb) as kb_indexed | eval GB = round(kb_indexed/1024/1024,2) | gauge GB 0 7 14 21 28&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I can then search the metrics logs reported from the systems like this&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index="Customer_Index" source="*metrics.log" per_index_thruput series="Customer_Index_group"  | stats sum(kb) as kb_indexed | eval GB = round(kb_indexed/1024/1024,2) | gauge GB 0 7 14 21 28&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;However these two numbers are very different.&lt;BR /&gt;
Granted the search on the _internal index runes much faster, but my users do not have access to the _internal index and they would like to know who much data there index is using.  I see a volume that is much larger on the search form index=_internal than they can see using index="Customer_Index".&lt;/P&gt;

&lt;P&gt;Why would the _internal index show more than the info from the $splunk/etc/var/log/splunk/metrics.log?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:19:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121909#M14436</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2020-09-28T16:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121910#M14437</link>
      <description>&lt;P&gt;Why does your customer index contain Splunk metrics logs?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 12:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121910#M14437</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-07T12:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121911#M14438</link>
      <description>&lt;P&gt;So that the customer [who did not want to install the splunk UF] can see and troubleshoot splunk UF issues.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 12:47:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121911#M14438</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2014-04-07T12:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121912#M14439</link>
      <description>&lt;P&gt;Are those metrics from the UFs or from the Indexers?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 12:49:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121912#M14439</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-07T12:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121913#M14440</link>
      <description>&lt;P&gt;they are for the UF.  I know this is maybe not best practice because the metrics.log's put in the customers index count against the license. &lt;/P&gt;

&lt;P&gt;Where is the best place to record the UF Metrics Logs so that they don't count agents the license and how could I give this info to the customer without letting them see too much.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 12:53:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121913#M14440</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2014-04-07T12:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121914#M14441</link>
      <description>&lt;P&gt;You could give them access to &lt;CODE&gt;_internal&lt;/CODE&gt; but restrict that to metrics about their index.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 13:08:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121914#M14441</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-07T13:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121915#M14442</link>
      <description>&lt;P&gt;Thanks for helping Martin, I really appreciate it.&lt;/P&gt;

&lt;P&gt;So How would I do that.  All the customer users are in a group/Role.  The group has access to there index.&lt;/P&gt;

&lt;P&gt;I would give them access to the _internal but how do I restrict access in only the _internal to the search term [series="Customer_Index_group"]&lt;/P&gt;

&lt;P&gt;I am on version 4.3.1, build 119532 PS will be onsite to help with the upgrade in 8 weeks.  Until then I can not upgrade.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:19:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121915#M14442</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2020-09-28T16:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121916#M14443</link>
      <description>&lt;P&gt;You give their role access to &lt;CODE&gt;_internal&lt;/CODE&gt; and add this to their search restriction terms:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index!=_internal OR (source=*metrics.log series="Customer_Index"))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In this fashion you could also give them access to their entire UF logs by adding their hosts (or a host tag) here.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.1/Admin/Addandeditroles#Search_filter_format"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.1/Admin/Addandeditroles#Search_filter_format&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 13:22:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121916#M14443</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-07T13:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121917#M14444</link>
      <description>&lt;P&gt;I will try this out as soon as I can.  Could you add this as your answer and if it works I can give you credit for the answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 13:27:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121917#M14444</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2014-04-07T13:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121918#M14445</link>
      <description>&lt;P&gt;this is the final filer if anyone is interested.  Thanks Martin for getting me there&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index=customer_index OR (index=_internal AND series="customer_index")&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2014 20:33:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121918#M14445</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2014-04-08T20:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: Index Volume, Licence Use Question</title>
      <link>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121919#M14446</link>
      <description>&lt;P&gt;I recommend keeping the restriction on the &lt;CODE&gt;source&lt;/CODE&gt; field in &lt;CODE&gt;_internal&lt;/CODE&gt; - else they'll be able to see random events that happen to contain &lt;CODE&gt;series=customer_index&lt;/CODE&gt; caught by default key-value extraction.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2014 20:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Index-Volume-Licence-Use-Question/m-p/121919#M14446</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-08T20:35:51Z</dc:date>
    </item>
  </channel>
</rss>

