Hi community
I'm still a bit confused how Splunk is calculating the volume usage.
So far, I'm using the Free license (up to 500MB) and I tried to optimize my logging file as good as possible.
Today, my log file is 800KB big but when checking the License settings using Splunk Web, I see (Volume used today:) 11 MB?
How is this possible? Where is this extra data coming from?
I still have to verify the matters to mentioned, I sure will but as a potential quick fix. Might it help if I periodically remove the monitored file?
I believe that once the data is indexed by Splunk, it doesn't matter about the file?