Getting Data In

Indexed Data

harshavrath
Contributor

HI,

I have so far indexed 38,442 of data into Splunk, how much is it when converted to MB & what will happen when i cross my 500MB limit.?

Any Help is Appreciated,

Thanks.

Tags (3)
0 Karma
1 Solution

rje
Explorer

How much data an event takes up depends on how much data is associated with the event.

You can index 500MB/day on the free and trial licence. When you exceed this limit you are given a warning that you have exeeded your limit. You can get 5 of these warnings each month. After the fifth warning Splunk will stop indexing new data for the rest of the month. You can still search in the data you already have indexed, by no new data will be indexed into splunk until you either purchase a licence or a new month comes along.

So to answer the question in your comment, yes, you can index 400MB today and 400MB tomorrow without getting a licence warning. There is no limit on the amount of data indexed into Splunk other that the size of your HDD.

View solution in original post

rje
Explorer

How much data an event takes up depends on how much data is associated with the event.

You can index 500MB/day on the free and trial licence. When you exceed this limit you are given a warning that you have exeeded your limit. You can get 5 of these warnings each month. After the fifth warning Splunk will stop indexing new data for the rest of the month. You can still search in the data you already have indexed, by no new data will be indexed into splunk until you either purchase a licence or a new month comes along.

So to answer the question in your comment, yes, you can index 400MB today and 400MB tomorrow without getting a licence warning. There is no limit on the amount of data indexed into Splunk other that the size of your HDD.

harshavrath
Contributor

thanks for the info rje.

0 Karma

harshavrath
Contributor

The License usage states that 500MB/perDay so can i index 400MB of data today & 400MB of Data tomorrow.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...