Getting Data In

Indexed Data

harshavrath
Contributor

HI,

I have so far indexed 38,442 of data into Splunk, how much is it when converted to MB & what will happen when i cross my 500MB limit.?

Any Help is Appreciated,

Thanks.

Tags (3)
0 Karma
1 Solution

rje
Explorer

How much data an event takes up depends on how much data is associated with the event.

You can index 500MB/day on the free and trial licence. When you exceed this limit you are given a warning that you have exeeded your limit. You can get 5 of these warnings each month. After the fifth warning Splunk will stop indexing new data for the rest of the month. You can still search in the data you already have indexed, by no new data will be indexed into splunk until you either purchase a licence or a new month comes along.

So to answer the question in your comment, yes, you can index 400MB today and 400MB tomorrow without getting a licence warning. There is no limit on the amount of data indexed into Splunk other that the size of your HDD.

View solution in original post

rje
Explorer

How much data an event takes up depends on how much data is associated with the event.

You can index 500MB/day on the free and trial licence. When you exceed this limit you are given a warning that you have exeeded your limit. You can get 5 of these warnings each month. After the fifth warning Splunk will stop indexing new data for the rest of the month. You can still search in the data you already have indexed, by no new data will be indexed into splunk until you either purchase a licence or a new month comes along.

So to answer the question in your comment, yes, you can index 400MB today and 400MB tomorrow without getting a licence warning. There is no limit on the amount of data indexed into Splunk other that the size of your HDD.

harshavrath
Contributor

thanks for the info rje.

0 Karma

harshavrath
Contributor

The License usage states that 500MB/perDay so can i index 400MB of data today & 400MB of Data tomorrow.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...