Installation

Does Splunk Ingestion license count the metadata into calculation?

kristen
Explorer

When logs arrive heavyforwarder, the forwarder may add some metadata into it based on the rule.

 

For example,

1. I have Syslog forwarder keeps on writing logs into the Heavy forwarder's disk space.

2. Heavyforwarder monitor logs written into various directories, e.g. [monitor:///var/log/remote/source_type_a/*.log]

3. Heavy forwarder add the source_type and host of the log, when it is indexing.

E.g. if it is forwarding the log from /var/log/remote/source_type_a/*.log, it add the sourcetype of log as source_type_a

 

Does these meta data also count into the indexer license limit?

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kristen,

no, license is countered on the raw log really indexed, not metedata.

In other words, if you filter your raw logs before indexing the filtered logs aren't countered.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...