Installation

Do multiple summary indexes affect license usage?

Paolo_Prigione
Builder

I know that since 4.1 summary indexing does not count against license anymore. However, what if I have multiple summary indexes?

According to this answer, I'd say more indexes would not affect the license, but just looked for a confirmation...

E.g.

  • summary -> the defauls summary index, residing on the search head.
  • summary1h -> stores results of scheduled aggregations having resolution of 1 hour, data kept for 1 month
  • summary1d -> stores results of scheduled aggregations having resolution of 1 day, data kept for 3 months

The last two sum-indexes would reside on a dedicate job server (with forwarding license).

Would this configuration affect license usage?

Thanks

Labels (1)
Tags (2)
1 Solution

Stephen_Sorkin
Splunk Employee
Splunk Employee

Adding more summary indexes will not affect license usage. No summary indexed data will count against the license.

View solution in original post

Stephen_Sorkin
Splunk Employee
Splunk Employee

Adding more summary indexes will not affect license usage. No summary indexed data will count against the license.

Paolo_Prigione
Builder

Thanks Stephen,
Paolo

0 Karma

aledantas2k12
Explorer

Wrong! If you overwrite the original sourcetype created by "|collect " (stash) it will count towards your licence.

0 Karma

ww9rivers
Contributor

Can Splunk please clarify? Is it true that, if sourcetype is changed to anything other than "stash", summary indexed data would count against license usage?

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...