<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk license calculations in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-license-calculations/m-p/105314#M7507</link>
    <description>&lt;P&gt;We have hit our limit and I am trying to work out the source of the overage.&lt;/P&gt;

&lt;P&gt;For today if I run&lt;/P&gt;

&lt;P&gt;index="_internal" source="*metrics.log" per_index_thruput | timechart&lt;BR /&gt;
span=1d sum(kb) by series&lt;/P&gt;

&lt;P&gt;The sum total don't make sense to me,&lt;/P&gt;

&lt;P&gt;It gives 35.30685103 GB and splunk is reporting 17,035 MB indexed, when I look at the license information.&lt;/P&gt;

&lt;P&gt;How do I get an accurate report that tells me what has been indexed, verse what splunk counts as indexed data.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 10:03:52 GMT</pubDate>
    <dc:creator>imacdonald2</dc:creator>
    <dc:date>2020-09-28T10:03:52Z</dc:date>
    <item>
      <title>Splunk license calculations</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-license-calculations/m-p/105314#M7507</link>
      <description>&lt;P&gt;We have hit our limit and I am trying to work out the source of the overage.&lt;/P&gt;

&lt;P&gt;For today if I run&lt;/P&gt;

&lt;P&gt;index="_internal" source="*metrics.log" per_index_thruput | timechart&lt;BR /&gt;
span=1d sum(kb) by series&lt;/P&gt;

&lt;P&gt;The sum total don't make sense to me,&lt;/P&gt;

&lt;P&gt;It gives 35.30685103 GB and splunk is reporting 17,035 MB indexed, when I look at the license information.&lt;/P&gt;

&lt;P&gt;How do I get an accurate report that tells me what has been indexed, verse what splunk counts as indexed data.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:03:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-license-calculations/m-p/105314#M7507</guid>
      <dc:creator>imacdonald2</dc:creator>
      <dc:date>2020-09-28T10:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk license calculations</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-license-calculations/m-p/105315#M7508</link>
      <description>&lt;P&gt;Looks like the way to calculate the numbers has changed in 4.2&lt;/P&gt;

&lt;P&gt;The following is giving me better numbers.&lt;/P&gt;

&lt;P&gt;index=_internal source=*license_usage.log | eval GB=b/1024/1024/1024 | timechart span=1d sum(GB) by st useother=0&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:03:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-license-calculations/m-p/105315#M7508</guid>
      <dc:creator>imacdonald2</dc:creator>
      <dc:date>2020-09-28T10:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk license calculations</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-license-calculations/m-p/105316#M7509</link>
      <description>&lt;P&gt;See also &lt;A href="http://splunk-base.splunk.com/answers/33773/send-alert-when-indexing-volume-limit-exceeded"&gt;http://splunk-base.splunk.com/answers/33773/send-alert-when-indexing-volume-limit-exceeded&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2011 20:49:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-license-calculations/m-p/105316#M7509</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2011-11-07T20:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk license calculations</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-license-calculations/m-p/105317#M7510</link>
      <description>&lt;P&gt;Check my answer to the question above along with my blog post I linked to in the answer.. there may be a few searches there that will appeal to you to track down the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2011 20:52:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-license-calculations/m-p/105317#M7510</guid>
      <dc:creator>joshd</dc:creator>
      <dc:date>2011-11-07T20:52:10Z</dc:date>
    </item>
  </channel>
</rss>

