Getting Data In

Indexed Data

harshavrath
Contributor

HI,

I have so far indexed 38,442 of data into Splunk, how much is it when converted to MB & what will happen when i cross my 500MB limit.?

Any Help is Appreciated,

Thanks.

Tags (3)
0 Karma
1 Solution

rje
Explorer

How much data an event takes up depends on how much data is associated with the event.

You can index 500MB/day on the free and trial licence. When you exceed this limit you are given a warning that you have exeeded your limit. You can get 5 of these warnings each month. After the fifth warning Splunk will stop indexing new data for the rest of the month. You can still search in the data you already have indexed, by no new data will be indexed into splunk until you either purchase a licence or a new month comes along.

So to answer the question in your comment, yes, you can index 400MB today and 400MB tomorrow without getting a licence warning. There is no limit on the amount of data indexed into Splunk other that the size of your HDD.

View solution in original post

rje
Explorer

How much data an event takes up depends on how much data is associated with the event.

You can index 500MB/day on the free and trial licence. When you exceed this limit you are given a warning that you have exeeded your limit. You can get 5 of these warnings each month. After the fifth warning Splunk will stop indexing new data for the rest of the month. You can still search in the data you already have indexed, by no new data will be indexed into splunk until you either purchase a licence or a new month comes along.

So to answer the question in your comment, yes, you can index 400MB today and 400MB tomorrow without getting a licence warning. There is no limit on the amount of data indexed into Splunk other that the size of your HDD.

harshavrath
Contributor

thanks for the info rje.

0 Karma

harshavrath
Contributor

The License usage states that 500MB/perDay so can i index 400MB of data today & 400MB of Data tomorrow.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...