Getting Data In

Can I decrease license usage by configuring props.conf and transforms.conf for selective indexing?

ctaf
Contributor

Hello,

I am trying to reduce the usage of my license and I found this post: https://answers.splunk.com/answers/42453/how-to-configure-selective-data-indexing.html

I was wondering if, by applying processing (props.conf) and transformation (transforms.conf), can I reduce the usage?

How does Splunk count the license usage? In this doc page:
http://docs.splunk.com/Documentation/Splunk/6.1/Admin/HowSplunklicensingworks
is written it takes in account "indexing", but it also says indexing is composed of data input.

Thank you,

0 Karma
1 Solution

jeffland
SplunkTrust
SplunkTrust

License is used for what you write into your index from your inputs, i.e. after parsing and all that. That means you can do what is mentioned in your link and it will decrease your license usage.

View solution in original post

0 Karma

jlaw
Splunk Employee
Splunk Employee

See this docs topic about using props and transforms to route and filter data (it's also linked from that licensing topic you pasted):

http://docs.splunk.com/Documentation/Splunk/6.3.1/Forwarding/Routeandfilterdatad

jeffland
SplunkTrust
SplunkTrust

License is used for what you write into your index from your inputs, i.e. after parsing and all that. That means you can do what is mentioned in your link and it will decrease your license usage.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...