Installation

Is license usage metered on raw data only?

rroberts
Splunk Employee
Splunk Employee

Is license usage metered on raw data only or does it include hosts. data,  source types. data, sources, and extracted search terms (assuming this is strings.data) as well?

Labels (1)
Tags (1)
1 Solution

dwaddle
SplunkTrust
SplunkTrust

License usage is based on your raw data volumes, not counting any data in the _internal index or any summary index. Based on your question, I assume you're looking in the bucket directory structure at these files. The rawdata files themselves don't necessarily correlate to license usage because they are compressed.

View solution in original post

woodcock
Esteemed Legend

License is calculated against raw data and does not include the size of your metadata or indexes into your raw data.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

License usage is based on your raw data volumes, not counting any data in the _internal index or any summary index. Based on your question, I assume you're looking in the bucket directory structure at these files. The rawdata files themselves don't necessarily correlate to license usage because they are compressed.

mabbez
New Member

Where do I check what is eating up at my license. been receiving the following message for the past few days:

Error in 'litsearch' command: Your Splunk license expired or you have exceeded your license limit too many times. Renew your Splunk license by visiting www.splunk.com/store or calling 866.GET.SPLUNK.
0 Karma

rroberts
Splunk Employee
Splunk Employee

So search terms, Metadata fields are not a factor in defaultdb?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...