Hi all!
We have configured a Db Connect v2 to read an Oracle database table. The query selects the records correctly and we get the lines indexed in splunk with no issue. The only problem is that the license volume consumed is exceeding the expected volume. Consider that for about 38 million records the size of the index in Splunk is about 18GB but the license volume consumed to load these records is about 70 GB. Who can explain this?
Thanks in advance
I believe the amount logged against your license is based on the amount you ingest, not on the size of the index. In your case, you pull 70 GB of data from the DB, but when it gets compressed it ends up being 18 GB on disk. Your compression ratio of 70:18, or about 4:1, isn't unheard of, especially with Database inputs.
The Splunk Health Overview app may have some good information in it to help.