Installation

Do multiple summary indexes affect license usage?

Paolo_Prigione
Builder

I know that since 4.1 summary indexing does not count against license anymore. However, what if I have multiple summary indexes?

According to this answer, I'd say more indexes would not affect the license, but just looked for a confirmation...

E.g.

  • summary -> the defauls summary index, residing on the search head.
  • summary1h -> stores results of scheduled aggregations having resolution of 1 hour, data kept for 1 month
  • summary1d -> stores results of scheduled aggregations having resolution of 1 day, data kept for 3 months

The last two sum-indexes would reside on a dedicate job server (with forwarding license).

Would this configuration affect license usage?

Thanks

Labels (1)
Tags (2)
1 Solution

Stephen_Sorkin
Splunk Employee
Splunk Employee

Adding more summary indexes will not affect license usage. No summary indexed data will count against the license.

View solution in original post

Stephen_Sorkin
Splunk Employee
Splunk Employee

Adding more summary indexes will not affect license usage. No summary indexed data will count against the license.

Paolo_Prigione
Builder

Thanks Stephen,
Paolo

0 Karma

aledantas2k12
Explorer

Wrong! If you overwrite the original sourcetype created by "|collect " (stash) it will count towards your licence.

0 Karma

ww9rivers
Contributor

Can Splunk please clarify? Is it true that, if sourcetype is changed to anything other than "stash", summary indexed data would count against license usage?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...