<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: License says twice as much data indexed as what index says in Installation</title>
    <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160051#M2506</link>
    <description>&lt;P&gt;It seems a little odd that it would always be exactly twice as much, though (this isn't the first time I've noticed this behavior).  It is all text in a similar format, but it seems like there should be SOME variation.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Feb 2014 20:43:50 GMT</pubDate>
    <dc:creator>redc</dc:creator>
    <dc:date>2014-02-20T20:43:50Z</dc:date>
    <item>
      <title>License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160047#M2502</link>
      <description>&lt;P&gt;I just indexed a data set.  According to the Indexes page in the Manager, the index is 126MB.  However, the Licensing page showed 252MB of consumption.  So far as I can tell, the data isn't being indexed twice.&lt;/P&gt;

&lt;P&gt;Anyone know what's going on?  I have several 100-300MB data sets to load and I don't want to overflow our 10GB license.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 20:28:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160047#M2502</guid>
      <dc:creator>redc</dc:creator>
      <dc:date>2014-02-20T20:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160048#M2503</link>
      <description>&lt;P&gt;You are seeing the compressed data in the index, and the uncompressed data in the license manager.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 20:31:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160048#M2503</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-02-20T20:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160049#M2504</link>
      <description>&lt;P&gt;Hi redc,&lt;/P&gt;

&lt;P&gt;license consumption is always based on the amount of the raw data not the amount of the data it has after the indexing process. This means for your 10Gb license, you can index 10Gb of raw data per day. For more details and information on the license process check the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/Admin/HowSplunklicensingworks"&gt;docs&lt;/A&gt; please.&lt;/P&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 20:34:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160049#M2504</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-02-20T20:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160050#M2505</link>
      <description>&lt;P&gt;aaah, I was typing too long &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 20:35:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160050#M2505</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-02-20T20:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160051#M2506</link>
      <description>&lt;P&gt;It seems a little odd that it would always be exactly twice as much, though (this isn't the first time I've noticed this behavior).  It is all text in a similar format, but it seems like there should be SOME variation.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 20:43:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160051#M2506</guid>
      <dc:creator>redc</dc:creator>
      <dc:date>2014-02-20T20:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160052#M2507</link>
      <description>&lt;P&gt;How large was the original data set?  It should match the license manager.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 20:48:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160052#M2507</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-02-20T20:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160053#M2508</link>
      <description>&lt;P&gt;If you have relatively consistent data, like syslog, you could have relatively consistent compression.  It sounds like you compression rate is 50%.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 20:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160053#M2508</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2014-02-20T20:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160054#M2509</link>
      <description>&lt;P&gt;It's SQL data being exported as XML through a sqlcmd.exe script, so I have no idea what the size is.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 20:54:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160054#M2509</guid>
      <dc:creator>redc</dc:creator>
      <dc:date>2014-02-20T20:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160055#M2510</link>
      <description>&lt;P&gt;Check out this wiki page.  It contains a number of index volume searches that you can run and might find useful.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume"&gt;http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 22:17:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160055#M2510</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-02-20T22:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160056#M2511</link>
      <description>&lt;P&gt;if you are loading a one time huge load.. it is ok to do a few times a month, as long as you don't get too many that would cause your search to stop working in splunk. After 30 days, those warnings will be gone and you can do it again. This helps you be able to load Historical data when needed without scaling up your splunk instance.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 22:46:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160056#M2511</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-02-20T22:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: License says twice as much data indexed as what index says</title>
      <link>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160057#M2512</link>
      <description>&lt;P&gt;The compression ratio for the raw data is actually better than 50%... That amount also contains index data such as .tsidx files.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 22:50:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-says-twice-as-much-data-indexed-as-what-index-says/m-p/160057#M2512</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-02-20T22:50:36Z</dc:date>
    </item>
  </channel>
</rss>

