Getting Data In

Over my license, Windows System Log eating it up with very few events

kholleran
Communicator

Hi,

I watch System Event logs across the enterprise but for very specific items. I do not send most events from my forwarders, only a select few event codes that I am interested in. This in turn results in few events from the system eventlog.

However, it seems to be eating up my license (suddenly). I have been running it in this fashion for a year and suddenly in the last couple days, I have had license issues.

I look at the License Volume and split by source, I see my system event log at up over my license amount by itself, but, for the same time period (24 hours), I only see 790 events. So I look at one particular half hour window and I see only 13 events, but Splunk is reporting it is over 32MB in size.

I am confused as to what is going on and I need to clear up the license issue in a hurry. Does anyone have any thoughts or has anyone seen this behavior before?

Thanks.

Kevin

0 Karma

ftk
Motivator

What do the events look like?

bojanz
Communicator

Maybe you indexed some old (historical) data? If you are just looking at the latest data you won't see it that way since it will be stored (as it should) with correct (older) dates?

0 Karma

kholleran
Communicator

This is not the case. I had a file system monitoring issue that put me over my license. I reset my license, removed the file system monitoring and now I have this problem.

I am now over my license again due to this. I see that every half hour period has only a few events but the size is over 30 MB. Its as if it is saying that each event is between 2 & 3 MB per event, which is ridiculous...

proctorgeorge
Path Finder

This happens especially when bringing new Splunk forwarders online, they try and report every historic log on the machine.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...