<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Storage: Splunk License options for data retention in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581337#M102502</link>
    <description>&lt;P&gt;The pricing model is named as Workload Pricing. It is available both Cloud and OnPrem with differently named capacity units. But the bigger issue is that it's price structure is "starting from 2-3TB/day" before it has competitive prices for normal use (if I recall right those price levels) &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But anyhow you could ask it, but don't surprised&amp;nbsp;&amp;nbsp;if they don't sell it to you.&lt;/P&gt;&lt;P&gt;You could also ask Predictice Pricing Program which has levels from 125GB to 2TB and 2TB+ levels.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jan 2022 14:23:01 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-01-17T14:23:01Z</dc:date>
    <item>
      <title>Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581203#M102484</link>
      <description>&lt;P&gt;We have a customer who has Splunk as main Security platform, but now they are trying to onboard other datasets for forensic/compliance/data retention purposes/application data. This doesn't need to be in Splunk as such, but any searchable tools like OpenSearch or similar. Before looking into such extra tools, wanted to understand if there is any provision with Splunk which would allow a data ingestion at cheaper cost (not counting to the main license cost or a cheaper license option?)&lt;/P&gt;&lt;P&gt;So the scenario is&lt;/P&gt;&lt;P&gt;(Security + compliance + application data) =&amp;gt; Splunk Heavy Forwarder -&amp;gt; (A) Security data to Splunk&amp;nbsp; &amp;amp;&amp;amp;&amp;nbsp; (B) Rest of data to a log retention service&lt;/P&gt;&lt;P&gt;Before going into this avenue, wanted to check if Splunk provide such a cheaper license option? i.e. for a log retention mode or non-important data (In future, they may have funding to move into Splunk, but not for atleast 6-8 months)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jan 2022 15:26:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581203#M102484</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2022-01-15T15:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581231#M102489</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/221196"&gt;@koshyk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk license is countered only on daily indexed volume, so there isn't in Splunk a cheaper way to ingest logs because all the indexed logs are countered in the Splunk license.&lt;/P&gt;&lt;P&gt;The question is: do you want to use Splunk for searching and monitoring or not?&lt;/P&gt;&lt;P&gt;if yes, the only way is to pay the license; if not, you have to design a different architecture with a different product outside Splunk.&lt;/P&gt;&lt;P&gt;Retention isn't relevant for Splunk costs, the only relevant parameter is the daily indexed log volume.&lt;/P&gt;&lt;P&gt;But if you want to store some logs only for compliance without using them in searches and monitoring, why don't you store them in a simple file system, outside Splunk?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 06:14:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581231#M102489</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-16T06:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581235#M102491</link>
      <description>&lt;P&gt;Well, I can imagine why someone would want to use splunk just for analytics/visualization without actually monitoring current data in it. Last month or so we had a question if splunk can be used as a visualization layer only (the data would come from db queries or something like that).&lt;/P&gt;&lt;P&gt;So yes, there is a possibility to - for example - store data outside of splunk, pull it into splunk search by custom command on search head and manipulate it there.&lt;/P&gt;&lt;P&gt;But this is a flawed solution, especially if we're talking about big volumes of data - we're not able to use splunk (parallel) search features in the first place.&lt;/P&gt;&lt;P&gt;So in the end in order to use splunk to ingest some data you have to have license for that data. If you want to lower your licensing requirement you might spread the data onboarding over a longer time period. For example&amp;nbsp; - if you have 10G worth of raw data, you can onboard it over a single day - for it you would&amp;nbsp; need a 10G license which would prove unnecessary for the rest of your licensing period. But you can onboard it over 10 days using just 1G daily license.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 09:18:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581235#M102491</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-01-16T09:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581242#M102492</link>
      <description>&lt;P&gt;Agreed. I understand the current license structure, but was checking if there was a other type of license within Splunk or if any of you have guys done it in a different way&lt;/P&gt;&lt;P&gt;Yeah, we have options to store outside Splunk. Of course, we may look into such a architecture using other products (as filesystem storage is bit clunky). There are few advanced thoughts as well, to store raw data in other tools and send a summary information to Splunk. So different avenues/thoughts, but wanted to see if there is any clever way within Splunk before venturing to other tools&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 11:39:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581242#M102492</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2022-01-16T11:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581243#M102493</link>
      <description>&lt;P&gt;Well, in my experience, many of the clients/users still don't understand their entire estate ! By the time, we reach someone would have estimated the data and said.. oh, its only 1000 windows &amp;amp; linux, so would be 10GB per day, while in reality the data would then start from "auditd", "applications" and far exceed 10x the initial estimate and suddently no funding available.&lt;/P&gt;&lt;P&gt;I personally feel, Splunk should have a secondary license to cater for trivial/less-important data and collection and when it is required to search, there should be charged separately. Many customers never realise the value until unless they see it.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 11:44:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581243#M102493</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2022-01-16T11:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581247#M102494</link>
      <description>&lt;P&gt;That's where Trial license and Splunk partners come into play.&lt;/P&gt;&lt;P&gt;You can deploy a low-scaled environment to appraise the average per-source license consumption and then scale it out accordingly (works with relatively homogenous environments). And you can ask your Splunk partner for help in estimating license consumption.&lt;/P&gt;&lt;P&gt;Sometimes, however, there's no telling beforehand - let's say you have a bunch of firewalls which are dumping flow and security events. You can to some extend calculate that if you have several millions of TCP sessions per hour, you wil surely won't go below 10GB per day &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; but you might have difficulty calculating the upper limit.&lt;/P&gt;&lt;P&gt;And, let's be honest, If you honestly think you're gonna need 1GB per day and it turns out your devices spit out 100 times that, there's something wrong with your logging setup, not necessarily with the license sizing. It's often also the case of "what you have" (i.e. we're pushing all the data that the device can possibly produce) vs. "what you need". Typical case from security realm - FireEye devices can forward both internal system logs as well as security events to an external log receiver. If you're deploying a log management solution for security, there's no point of logging the internal daemons' logs but it's typical for the admins to just forward everything. The difference is that if you're in a relatively "peaceful" environment, you might get just 20 or 50 security events per day whereas system logging produces several thousands or even millions events per day. That's when it's good if your Splunk partner has experience with more than Splunk alone and can help you with such cases.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 12:53:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581247#M102494</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-01-16T12:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581249#M102495</link>
      <description>&lt;P&gt;Consider Workload Pricing rather than an Ingest Pricinv.&amp;nbsp; With Workload Pricing, you pay based on the compute resources used instead of based on how much data is indexed.&amp;nbsp; See&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/software/pricing/faqs.html#workload-pricing" target="_blank"&gt;https://www.splunk.com/en_us/software/pricing/faqs.html#workload-pricing&lt;/A&gt;&amp;nbsp;for more.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 14:41:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581249#M102495</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-01-16T14:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581272#M102496</link>
      <description>&lt;P&gt;Are you sure Workload Pricing is available for the core Splunk Enterprise? Just asking because never worked with this licensing model. I know it works with Cloud but Splunk website says vaguely about "some on-premise offerings".&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 23:59:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581272#M102496</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-01-16T23:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581331#M102500</link>
      <description>&lt;P&gt;Not 100% sure because Splunk is a bit vague about pricing, but it's worth asking Sales about.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 13:29:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581331#M102500</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-01-17T13:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581336#M102501</link>
      <description>&lt;P&gt;Sure. The worst that can happen is that they say "no way" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 14:12:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581336#M102501</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-01-17T14:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581337#M102502</link>
      <description>&lt;P&gt;The pricing model is named as Workload Pricing. It is available both Cloud and OnPrem with differently named capacity units. But the bigger issue is that it's price structure is "starting from 2-3TB/day" before it has competitive prices for normal use (if I recall right those price levels) &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But anyhow you could ask it, but don't surprised&amp;nbsp;&amp;nbsp;if they don't sell it to you.&lt;/P&gt;&lt;P&gt;You could also ask Predictice Pricing Program which has levels from 125GB to 2TB and 2TB+ levels.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 14:23:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581337#M102502</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-17T14:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581348#M102503</link>
      <description>&lt;P class="lia-align-justify"&gt;thanks for the idea. upvoted. Do you have a rough idea if it is cheaper vs the default licensing methodology? or is it more of a question for Splunk Sales?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 15:44:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581348#M102503</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2022-01-17T15:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581349#M102504</link>
      <description>&lt;P&gt;great ideas. This is exactly I was looking for. Will get in touch with Sales on these topic/ideas&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 15:45:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581349#M102504</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2022-01-17T15:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Data Storage: Splunk License options for data retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581366#M102505</link>
      <description>&lt;P&gt;As there are counted all (v)CPUs which participate search (excl. LM) it will be more expensive for small ingestion data amounts.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 17:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Storage-Splunk-License-options-for-data-retention/m-p/581366#M102505</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-17T17:41:25Z</dc:date>
    </item>
  </channel>
</rss>

