Getting Data In

How much license value is utilized while indexing a file of 100Gb once it is in compressed format in indexer?

vikram_m
Path Finder

When a log file is brought inside the Splunk indexer after input phase it is compressed to almost 10% of its value. So if a 100Gb file is put onto indexer cluster say it gets compressed to 15 Gb, so how much indexer license will be used for the file to extract indexes from the raw data file indexer gets from forwarders? Is it 15Gb or 100Gb? Please suggest.

0 Karma
1 Solution

lguinn2
Legend

The data passes through the license meter before it is compressed and before the index files are created (which can be quite large).

So a 100Gb input source would use 100Gb of splunk license.

View solution in original post

aaraneta_splunk
Splunk Employee
Splunk Employee

Hi @vikram_m - Glad to hear that lguinn and ddrillic were able to provide helpful feedback. Please don't forget to resolve this post by clicking "Accept" below the best answer 🙂 Thanks!

0 Karma

ddrillic
Ultra Champion

Please note that data that is eliminated during the parsing process doesn't count against the daily quota.

About the parsing phase at How to Filter Unwanted Data without adding to Splunk Daily Indexing Volume

It says -

alt text

vikram_m
Path Finder

Thank ddrillic this was helpful. 🙂

0 Karma

lguinn2
Legend

The data passes through the license meter before it is compressed and before the index files are created (which can be quite large).

So a 100Gb input source would use 100Gb of splunk license.

vikram_m
Path Finder

Thanks lguinn this was helpful.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...