<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding more forwarders when licenses are almost maxed out in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262585#M50375</link>
    <description>&lt;P&gt;-- .. or will it only index up to my license amount of 100GB then grab the rest later when space is available&lt;/P&gt;

&lt;P&gt;It doesn't seem that such logic exists in the product. &lt;/P&gt;

&lt;P&gt;As a workaround you can control it via the &lt;CODE&gt;ignoreOlderThan&lt;/CODE&gt; parameter in the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; file - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
index=xxxx
ignoreOlderThan = 4d
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can set it up for 4 days, for example, and increase it on a daily basis and go further back in time while monitoring the license usage.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Jul 2016 17:54:58 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2016-07-15T17:54:58Z</dc:date>
    <item>
      <title>Adding more forwarders when licenses are almost maxed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262582#M50372</link>
      <description>&lt;P&gt;If I have a 100GB licenses and my current indexing rate is around 90GB/day and I turned a forwarder on which had 15GB of log files total but only produced around 1GB/daily. Would this cause me to go over my current 100GB licenses since it will retroactively index all the logs or will it only index up to my license amount of 100GB then grab the rest later when space is available? &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 17:28:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262582#M50372</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-07-15T17:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more forwarders when licenses are almost maxed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262583#M50373</link>
      <description>&lt;P&gt;It all depends on how you configure your inputs.&lt;BR /&gt;
If you want your forwarder to backfill all the existing logs and not just real-time ones, then it is likely going to blow your license that day based on what you are saying, but because you can violate the license up to 5 times within a 30 day period before it stops searching, I wouldn't worry too much.&lt;/P&gt;

&lt;P&gt;Worst case contact your account manager and request a license violation reset explaining that you are backfilling old logs. It shouldn't be a problem.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 17:38:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262583#M50373</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-07-15T17:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more forwarders when licenses are almost maxed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262584#M50374</link>
      <description>&lt;P&gt;By default it will backfill retroactively right? What &lt;CODE&gt;.conf&lt;/CODE&gt; file would I modify to prevent this?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 17:44:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262584#M50374</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-07-15T17:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more forwarders when licenses are almost maxed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262585#M50375</link>
      <description>&lt;P&gt;-- .. or will it only index up to my license amount of 100GB then grab the rest later when space is available&lt;/P&gt;

&lt;P&gt;It doesn't seem that such logic exists in the product. &lt;/P&gt;

&lt;P&gt;As a workaround you can control it via the &lt;CODE&gt;ignoreOlderThan&lt;/CODE&gt; parameter in the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; file - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
index=xxxx
ignoreOlderThan = 4d
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can set it up for 4 days, for example, and increase it on a daily basis and go further back in time while monitoring the license usage.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 17:54:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262585#M50375</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-07-15T17:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Adding more forwarders when licenses are almost maxed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262586#M50376</link>
      <description>&lt;P&gt;If you have 15GB of log files but only want to read 1GB/daily then configure your inputs.conf to read just today's file.&lt;/P&gt;

&lt;P&gt;For example, assuming there's 15GB of *.log files under /var/log that you want to read: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/*.log] -&amp;gt; this will tell Splunk to read them all

[monitor:///var/log/*.log] -&amp;gt; this will tell Splunk to ignore files older than 1 day
ignoreOlderThan = 1d
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you still need those 15GB of logs then go for it as you will only violate the license one day out of the 5 you have on any 30 day period.&lt;/P&gt;

&lt;P&gt;Or maybe you want to configure Splunk to read the 15GB logs on a weekend when the license usage is lower.&lt;/P&gt;

&lt;P&gt;There are plenty of options and none of them is wrong&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 17:56:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-more-forwarders-when-licenses-are-almost-maxed-out/m-p/262586#M50376</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-07-15T17:56:28Z</dc:date>
    </item>
  </channel>
</rss>

