Deployment Architecture

Volume used

itionet
New Member

Hi Everyone. I recently installed the free version of Splunk. I have configured it to read data from only one data source, Netflow from a single router. Over the last 5 days, only 7MB of Netflow data has been collected. However, the volume used in the licensing is showing that I have used 3GB so far today. Can anyone shed some light as to why this is possibly happening?

Thanks,
Matt

Tags (1)
0 Karma

somesoni2
Revered Legend

Run following query and you can check the license usage by index. Based on this you can get to know where your license capacity is utilized.

index=_internal source=*license_usage.log sourcetype=splunkd | timechart span=1d sum(b) as bytes by idx limit=0| eval MB=round(bytes/1024/1024/1024,3)

Other variation your can try is using the sourcetype

index=_internal source=*license_usage.log sourcetype=splunkd | timechart span=1d sum(b) as bytes by st limit=0| eval MB=round(bytes/1024/1024/1024,3)
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...