<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk indexing question in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341439#M6570</link>
    <description>&lt;P&gt;What do you mean by "usage"?  Are you referring to licensing or something else?&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2017 15:10:28 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2017-08-02T15:10:28Z</dc:date>
    <item>
      <title>Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341438#M6569</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm trying to read how splunk indexing and usage works and still couldn't figure it our.  Here is an example, we have around 3GB log file we need to analyze every  15 minutes, if we do search entry and if we get result of 5kb results of data,  How would it show in  usage?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 13:47:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341438#M6569</guid>
      <dc:creator>ananthan123</dc:creator>
      <dc:date>2017-08-02T13:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341439#M6570</link>
      <description>&lt;P&gt;What do you mean by "usage"?  Are you referring to licensing or something else?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 15:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341439#M6570</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-08-02T15:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341440#M6571</link>
      <description>&lt;P&gt;Yes,  licensing usage.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 15:17:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341440#M6571</guid>
      <dc:creator>ananthan123</dc:creator>
      <dc:date>2017-08-02T15:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341441#M6572</link>
      <description>&lt;P&gt;Hi ananthan123,&lt;BR /&gt;
about indexing, Splunk indexes all the logs that it receives from all the inputs (local or remote) and license counts the daily volume of indexed logs.&lt;BR /&gt;
In searches, Splunk shows the all the events that matches the search terms: if you have few events you have few traffic, if you have many events you have more traffic, aniway searches don't affect license consuption, they are important only in infrastructure capacity planning.&lt;BR /&gt;
Could you share more details about your needs?&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe &lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 15:24:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341441#M6572</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-02T15:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341442#M6573</link>
      <description>&lt;P&gt;Thank you so much Giuseppe. This is what I would like to know. If I understand  correctly,  If we do searches it won't affect license consumption. It will only  calculate based on events and logs what we are indexing.  Am  I right?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 15:36:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341442#M6573</guid>
      <dc:creator>ananthan123</dc:creator>
      <dc:date>2017-08-02T15:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341443#M6574</link>
      <description>&lt;P&gt;Yes, the total logs you daily indexed.&lt;BR /&gt;
You can exceed the daily quota without a violation for 5 times in 30 solar days with a license and 3 times with the free license.&lt;BR /&gt;
After you need a violation code to unlock your license (during violation logs are aniway indexed but you cannot run searches).&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;BR /&gt;
P.S. if your satisfied of this answer, please accept it.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 15:52:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341443#M6574</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-02T15:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341444#M6575</link>
      <description>&lt;P&gt;Thank you very much. how does forwarder metric log and indexer metric log works?  Forwarder pass the local metric.log data to indexer  and indexer merges with local metric.log and then do the indexing?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 16:04:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341444#M6575</guid>
      <dc:creator>ananthan123</dc:creator>
      <dc:date>2017-08-02T16:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341445#M6576</link>
      <description>&lt;P&gt;No indexer counts the really indexed logs, logs sent by forwarders  aren't added to the license consuption.&lt;BR /&gt;
Infact you can filter logs received by indexers before indexing and discarded logs don't consume license.&lt;BR /&gt;
At the same time Splunk internal logs are indexed but not added to the license consumption.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe &lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 16:55:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341445#M6576</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-02T16:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341446#M6577</link>
      <description>&lt;P&gt;Thank  you, when you say internal logs, does it mean indexer's log files?  for an example metric.log file?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 19:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341446#M6577</guid>
      <dc:creator>ananthan123</dc:creator>
      <dc:date>2017-08-02T19:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341447#M6578</link>
      <description>&lt;P&gt;All Splunk logs of all Splunk servers, also Forwarders.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe &lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 19:47:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341447#M6578</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-02T19:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341448#M6579</link>
      <description>&lt;P&gt;Thank  you very much  Giuesppe.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 20:03:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-indexing-question/m-p/341448#M6579</guid>
      <dc:creator>ananthan123</dc:creator>
      <dc:date>2017-08-02T20:03:24Z</dc:date>
    </item>
  </channel>
</rss>

