Getting Data In

License Capping

abhijeet01
Path Finder

We have a 16GB Indexing License for one applicatiom , which for the first time we have exceeded the limit. I would like to know if there is a way to tell Splunk to stop this indexing input if the license quota hits > 90%.

Can we do it by Script or how and is there any other solution for this ?

Thanks.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @abhijeet01,

no, there isn't the choice to automatically stop indexing when the license arrives to a  limit (e.g. 90%), infact Splunk continues to index data even if you are in License violation.

In my experience, you have to choices:

  • to set an alert when you arrive to a threshold (e.g. 90%) and manually intervene to close some inputs;
  • analyze your flows and identify your license consuption.

I usually do the second, in this case you have to analize your logs;

  • so if you exceed the license by a little, you could identify if there's something to filter out because you don't need it and you can be into the license limit,
  • if instead you exceed the license too much to filter events, you have to buy a larger license.

If instead your license exceeding is occasional, remember that you can exceed the license 45 times in 60 days (with the new rules, and 5 times in 30 days wi the older), so it isn't a problem some occasional exceed.

As I said, you have to analyze your flows and design your system finding the correct license you need.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...