Getting Data In

How does Splunk calculate daily indexing limit

malukisses
Engager

Hello,

We've been downloading between 200 and 250 MB of logs and adding them to Splunk every day.
Yesterday we downloaded 218MB, and this morning when I came in, I had a "indexing volume exceeded" warning.

Now my free license says I can index up to 500MB a day.

The only explanation for the warning would be if 500MB "indexed" doesn't necessarily mean 500MB of logs.

How does Splunk calculate the "indexing volume" and what would that translate in terms of log size?

lukejadamec
Super Champion

Indexing volume is the uncompressed log volume, and it does not include Splunk internal logging.
The index volume is measured from midnight to midnight.
You can use Deployment Monitor to see who indexed what and how much for the day the volume was exceeded. If you don't have Deployment Monitor installed, then you can use the searches I posted in this answer to see who was indexing what and how much:

http://answers.splunk.com/answers/107385/splunk-internal-fields-on-reports

0 Karma

yannK
Splunk Employee
Splunk Employee

for questions about what is my volume, details of searches are here
http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...