Deployment Architecture

Volume used

itionet
New Member

Hi Everyone. I recently installed the free version of Splunk. I have configured it to read data from only one data source, Netflow from a single router. Over the last 5 days, only 7MB of Netflow data has been collected. However, the volume used in the licensing is showing that I have used 3GB so far today. Can anyone shed some light as to why this is possibly happening?

Thanks,
Matt

Tags (1)
0 Karma

somesoni2
Revered Legend

Run following query and you can check the license usage by index. Based on this you can get to know where your license capacity is utilized.

index=_internal source=*license_usage.log sourcetype=splunkd | timechart span=1d sum(b) as bytes by idx limit=0| eval MB=round(bytes/1024/1024/1024,3)

Other variation your can try is using the sourcetype

index=_internal source=*license_usage.log sourcetype=splunkd | timechart span=1d sum(b) as bytes by st limit=0| eval MB=round(bytes/1024/1024/1024,3)
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...