<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk cloud kv_mode=json vs indexed_extractions=json license usage in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-cloud-kv-mode-json-vs-indexed-extractions-json-license/m-p/749005#M3881</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would like to know if there is a consumption gap between this 2 indexation mode in the splunk cloud license usage. I mean, which one will cost the most, with structured log(json).&lt;BR /&gt;What I understand:&lt;/P&gt;&lt;P&gt;indexed_extractions=json ==&amp;gt; fields are extracted at index time and could increase the size of tsidx and so license usage and cost&lt;/P&gt;&lt;P&gt;kv_mode=json ==&amp;gt; fields extracted at search time, and should not impact license usage.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Am I correct?&lt;BR /&gt;Thanks for your confirmation&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Nordine&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jul 2025 08:25:15 GMT</pubDate>
    <dc:creator>nordinethales</dc:creator>
    <dc:date>2025-07-01T08:25:15Z</dc:date>
    <item>
      <title>splunk cloud kv_mode=json vs indexed_extractions=json license usage</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-cloud-kv-mode-json-vs-indexed-extractions-json-license/m-p/749005#M3881</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would like to know if there is a consumption gap between this 2 indexation mode in the splunk cloud license usage. I mean, which one will cost the most, with structured log(json).&lt;BR /&gt;What I understand:&lt;/P&gt;&lt;P&gt;indexed_extractions=json ==&amp;gt; fields are extracted at index time and could increase the size of tsidx and so license usage and cost&lt;/P&gt;&lt;P&gt;kv_mode=json ==&amp;gt; fields extracted at search time, and should not impact license usage.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Am I correct?&lt;BR /&gt;Thanks for your confirmation&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Nordine&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 08:25:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-cloud-kv-mode-json-vs-indexed-extractions-json-license/m-p/749005#M3881</guid>
      <dc:creator>nordinethales</dc:creator>
      <dc:date>2025-07-01T08:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: splunk cloud kv_mode=json vs indexed_extractions=json license usage</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-cloud-kv-mode-json-vs-indexed-extractions-json-license/m-p/749013#M3882</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234786"&gt;@nordinethales&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are correct, there might be significant difference in Splunk Cloud license usage between INDEXED_EXTRACTIONS=json and KV_MODE=json&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;INDEXED_EXTRACTIONS=json - Fields are extracted at index time and stored, which increases the size and license usage&lt;BR /&gt;KV_MODE=json - Fields are only extracted at search time, so license usage is based on the raw data size.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Also you can refer this #&lt;A href="https://splunk.github.io/splunk-add-on-for-crowdstrike-fdr/fieldextractions/" target="_blank"&gt;https://splunk.github.io/splunk-add-on-for-crowdstrike-fdr/fieldextractions/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 09:36:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-cloud-kv-mode-json-vs-indexed-extractions-json-license/m-p/749013#M3882</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-07-01T09:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: splunk cloud kv_mode=json vs indexed_extractions=json license usage</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-cloud-kv-mode-json-vs-indexed-extractions-json-license/m-p/749016#M3883</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234786"&gt;@nordinethales&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Splunk Cloud ingestion (assuming you have an ingest based license, not SVC license) is based on the raw uncompressed data size ingested, rather than indexed fields, apart from metrics which are each counted as 150 bytes.&lt;/P&gt;&lt;P&gt;For storage this is also based on the uncompressed raw ingest.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For more info check out&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/get-started/service-terms-and-policies/9.3.2411/information-about-the-service/splunk-cloud-platform-service-details" target="_blank"&gt;https://help.splunk.com/en/splunk-cloud-platform/get-started/service-terms-and-policies/9.3.2411/information-about-the-service/splunk-cloud-platform-service-details&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 10:47:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-cloud-kv-mode-json-vs-indexed-extractions-json-license/m-p/749016#M3883</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-01T10:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: splunk cloud kv_mode=json vs indexed_extractions=json license usage</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-cloud-kv-mode-json-vs-indexed-extractions-json-license/m-p/749018#M3884</link>
      <description>&lt;P&gt;As far as I remember, the license consumption for Cloud in the ingest-based option is the same as on-prem one which means the event is measured by its _raw part just prior to indexing. This means that:&lt;/P&gt;&lt;P&gt;1) However you modify your event prior to indexing it in terms of the raw event contents (like cutting out some headers or unnecessary trailing parts) will affect your license usage&lt;/P&gt;&lt;P&gt;2) Indexed fields which are saved in the tsidx files but are not "exploding" your _raw event contents do not affect your license usage.&lt;/P&gt;&lt;P&gt;Having said that - indexed extractions are very rarely the way to go but not for license-related reasons.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 10:52:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-cloud-kv-mode-json-vs-indexed-extractions-json-license/m-p/749018#M3884</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-07-01T10:52:22Z</dc:date>
    </item>
  </channel>
</rss>

