- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does the length of metadata fields and its value such as time, host, source and sourcetype count against license consumption?
For example, the following HEC JSON has a length of 212 characters but the event (_raw) is only 20 characters, is license calculated against the total json length or _raw length?
{
"time":1437522387,
"host":"dataserver01.applicationmonitoring.com",
"source":"/var/logs/application_monitoring.log",
"sourcetype":"application_status",
"event":{
"message":"Seems OK"
}
}
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

When using the HEC event format and sending to the event endpoint (not raw endpoint) only the "event" field should be rated. The metadata fields are not.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

When using the HEC event format and sending to the event endpoint (not raw endpoint) only the "event" field should be rated. The metadata fields are not.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you @mattymo, I was able to test and confirm your answer.
The following event sent to HEC would incur license usage of 22 bytes.
{
"index":"summary_is_temp",
"host":"testing_hec_license_consumption.acme.org",
"source":"/var/logs/application_monitoring.log",
"sourcetype":"application_status",
"event":{
"message":"Seems OK"
}
}
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

kudos to you to mistrusting and verifying!!! 🙂
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @johnhuang,
it seems the also the raw log is 212 chars not 20.
Anyway, License consuption is calculated only on the volume of _raw logs indexed:
if your event has 212 chars, it causes a License consuption of 212 bytes, even if you extract from it many fields.
Ciao.
Giuseppe
