<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: May I know how Splunk calculate license usage for Packet collections in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/May-I-know-how-Splunk-calculate-license-usage-for-Packet/m-p/304196#M2850</link>
    <description>&lt;P&gt;Hi SSievert&lt;/P&gt;

&lt;P&gt;Thanks for your answer, actually we are planning to deploy Splunk in our Environment, we are evaluating license status if it will be enough for current packet capturing. Currently we use another Security product that also can capturing packets and we write rules to do some security related alerts/incidents creation, and also dig out some potential risks in our environment. So besides logs, packet capturing and investigation is also very important for us.&lt;/P&gt;

&lt;P&gt;We setup many Use cases that may index packet meta data, like clear text password finding, Botnet tracing and IOC detection, etc.&lt;/P&gt;

&lt;P&gt;BR&lt;BR /&gt;
Nelson&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2017 14:22:49 GMT</pubDate>
    <dc:creator>nelson_ye</dc:creator>
    <dc:date>2017-10-13T14:22:49Z</dc:date>
    <item>
      <title>May I know how Splunk calculate license usage for Packet collections</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/May-I-know-how-Splunk-calculate-license-usage-for-Packet/m-p/304194#M2848</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;

&lt;P&gt;I want to know how Splunk will calculate license usages for packets collection?&lt;BR /&gt;
Currently what we are doing is setup monitor sessions on Cisco switches, and then monitor interested vlans' traffics to packet collectors.&lt;BR /&gt;
For example, i have one packet capture device that have one NIC capturing packets, below are 24 hours collected pkts:&lt;BR /&gt;
EM2:8749745734122 bytes = 1018GB&lt;/P&gt;

&lt;P&gt;So will both those 1018 GB being calculated into license usage?&lt;/P&gt;

&lt;P&gt;BR&lt;BR /&gt;
Nelson&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 06:56:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/May-I-know-how-Splunk-calculate-license-usage-for-Packet/m-p/304194#M2848</guid>
      <dc:creator>nelson_ye</dc:creator>
      <dc:date>2017-10-12T06:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: May I know how Splunk calculate license usage for Packet collections</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/May-I-know-how-Splunk-calculate-license-usage-for-Packet/m-p/304195#M2849</link>
      <description>&lt;P&gt;Nelson,&lt;BR /&gt;
this is well documented &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/HowSplunklicensingworks"&gt;here&lt;/A&gt;.&lt;BR /&gt;
Splunk license usage is based on the actual raw bytes written to disk during indexing in a 24hr period. If you index your packet captures into Splunk and the data represents 1018GB, this is what will be used in license usage calculation.&lt;/P&gt;

&lt;P&gt;What is your use case for indexing pcap data...?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 07:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/May-I-know-how-Splunk-calculate-license-usage-for-Packet/m-p/304195#M2849</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-12T07:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: May I know how Splunk calculate license usage for Packet collections</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/May-I-know-how-Splunk-calculate-license-usage-for-Packet/m-p/304196#M2850</link>
      <description>&lt;P&gt;Hi SSievert&lt;/P&gt;

&lt;P&gt;Thanks for your answer, actually we are planning to deploy Splunk in our Environment, we are evaluating license status if it will be enough for current packet capturing. Currently we use another Security product that also can capturing packets and we write rules to do some security related alerts/incidents creation, and also dig out some potential risks in our environment. So besides logs, packet capturing and investigation is also very important for us.&lt;/P&gt;

&lt;P&gt;We setup many Use cases that may index packet meta data, like clear text password finding, Botnet tracing and IOC detection, etc.&lt;/P&gt;

&lt;P&gt;BR&lt;BR /&gt;
Nelson&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 14:22:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/May-I-know-how-Splunk-calculate-license-usage-for-Packet/m-p/304196#M2850</guid>
      <dc:creator>nelson_ye</dc:creator>
      <dc:date>2017-10-13T14:22:49Z</dc:date>
    </item>
  </channel>
</rss>

