Deployment Architecture

Volume used

itionet
New Member

Hi Everyone. I recently installed the free version of Splunk. I have configured it to read data from only one data source, Netflow from a single router. Over the last 5 days, only 7MB of Netflow data has been collected. However, the volume used in the licensing is showing that I have used 3GB so far today. Can anyone shed some light as to why this is possibly happening?

Thanks,
Matt

Tags (1)
0 Karma

somesoni2
Revered Legend

Run following query and you can check the license usage by index. Based on this you can get to know where your license capacity is utilized.

index=_internal source=*license_usage.log sourcetype=splunkd | timechart span=1d sum(b) as bytes by idx limit=0| eval MB=round(bytes/1024/1024/1024,3)

Other variation your can try is using the sourcetype

index=_internal source=*license_usage.log sourcetype=splunkd | timechart span=1d sum(b) as bytes by st limit=0| eval MB=round(bytes/1024/1024/1024,3)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...