Installation

Is license usage metered on raw data only?

rroberts
Splunk Employee
Splunk Employee

Is license usage metered on raw data only or does it include hosts. data,  source types. data, sources, and extracted search terms (assuming this is strings.data) as well?

Labels (1)
Tags (1)
1 Solution

dwaddle
SplunkTrust
SplunkTrust

License usage is based on your raw data volumes, not counting any data in the _internal index or any summary index. Based on your question, I assume you're looking in the bucket directory structure at these files. The rawdata files themselves don't necessarily correlate to license usage because they are compressed.

View solution in original post

woodcock
Esteemed Legend

License is calculated against raw data and does not include the size of your metadata or indexes into your raw data.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

License usage is based on your raw data volumes, not counting any data in the _internal index or any summary index. Based on your question, I assume you're looking in the bucket directory structure at these files. The rawdata files themselves don't necessarily correlate to license usage because they are compressed.

mabbez
New Member

Where do I check what is eating up at my license. been receiving the following message for the past few days:

Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.
0 Karma

rroberts
Splunk Employee
Splunk Employee

So search terms, Metadata fields are not a factor in defaultdb?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...