Installation

Are there best practices for controlling my daily license quota used per pool?

kgraw21
New Member

I am a newbie and just getting started. I'm only pulling local data from the Splunk Server. I do have a few apps installed for Active directory and Utilization Monitor. I have a 5GB limit limit and my daily usage is already at 2.267GB of usage. What happens when I set up forwarders for at least 60 additional servers? Is my license big enough? Is there a best practice documentation for newbies?

Labels (2)
0 Karma

maciep
Champion

It all depends on the data you want to bring in. On those 60 forwarders, do you know what logs you're looking to ingest? Can you do some manual calculations to determine how much per day that would be. Will each forwarder report the same type of data? Meaning, can you install on one and extrapolate from there?

Are you bringing in anything today that you don't need? Maybe something being ingested by default by the apps you installed?

The documentation is worth a read. But at a high-level, if you go over your license for a day then you get a warning. If you get 5 warnings in a rolling 30 day period then you're in violation. At that point, you won't be able to search your data, however it will still be indexed. You would need to request a reset key to remove the warnings and start - something you'd get from your sales contact or support.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...