Getting Data In

How much license value is utilized while indexing a file of 100Gb once it is in compressed format in indexer?

vikram_m
Path Finder

When a log file is brought inside the Splunk indexer after input phase it is compressed to almost 10% of its value. So if a 100Gb file is put onto indexer cluster say it gets compressed to 15 Gb, so how much indexer license will be used for the file to extract indexes from the raw data file indexer gets from forwarders? Is it 15Gb or 100Gb? Please suggest.

0 Karma
1 Solution

lguinn2
Legend

The data passes through the license meter before it is compressed and before the index files are created (which can be quite large).

So a 100Gb input source would use 100Gb of splunk license.

View solution in original post

aaraneta_splunk
Splunk Employee
Splunk Employee

Hi @vikram_m - Glad to hear that lguinn and ddrillic were able to provide helpful feedback. Please don't forget to resolve this post by clicking "Accept" below the best answer 🙂 Thanks!

0 Karma

ddrillic
Ultra Champion

Please note that data that is eliminated during the parsing process doesn't count against the daily quota.

About the parsing phase at How to Filter Unwanted Data without adding to Splunk Daily Indexing Volume

It says -

alt text

vikram_m
Path Finder

Thank ddrillic this was helpful. 🙂

0 Karma

lguinn2
Legend

The data passes through the license meter before it is compressed and before the index files are created (which can be quite large).

So a 100Gb input source would use 100Gb of splunk license.

vikram_m
Path Finder

Thanks lguinn this was helpful.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...