Installation

Metrics Licensing - What Classifies as an event?

tlscelsi
Engager

Hi all,

Just a quick question about licensing for metrics. I understand that there is a fixed size of 150 bytes for each event that gets indexed. What i was wondering was what is classified as an event. If i have raw data that comes in that looks like this:

Date=2019-05-10_02:24:12_+0000,collection=Network Interface,object=Network Interface,counter=Bytes Sent/sec,instance=veth32fe058,Value=0
Date=2019-05-10_02:24:12_+0000,collection=Network Interface,object=Network Interface,counter=Bytes Sent/sec,instance=vethab72d6b,Value=0
Date=2019-05-10_02:24:12_+0000,collection=Network Interface,object=Network Interface,counter=Bytes Sent/sec,instance=veth9713e61,Value=0
Date=2019-05-10_02:24:12_+0000,collection=Network Interface,object=Network Interface,counter=Bytes Sent/sec,instance=br-024d0abf8854,Value=0
Date=2019-05-10_02:24:12_+0000,collection=Network Interface,object=Network Interface,counter=Bytes Sent/sec,instance=eth0,Value=8253.44
Date=2019-05-10_02:24:12_+0000,collection=Network Interface,object=Network Interface,counter=Bytes Sent/sec,instance=veth0a123e0,Value=0
Date=2019-05-10_02:24:12_+0000,collection=Network Interface,object=Network Interface,counter=Bytes Sent/sec,instance=vethad472a8,Value=0
Date=2019-05-10_02:24:12_+0000,collection=Network Interface,object=Network Interface,counter=Bytes Sent/sec,instance=docker0,Value=0

That is then parsed so that each line becomes a data point within the metric index, does that mean i consume one set of 150 bytes from my license, or is it 150 bytes for each line that is parsed into the index? In this case there are 8 lines, does this mean i am charged 150 * 8 bytes from my license?

My current understanding is that this set of incoming data would corresponds to 8 150 byte chunks of license being charged. Am i correct?

Thanks in advance!!

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You are correct. Each line is a separate event.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You are correct. Each line is a separate event.

---
If this reply helps you, Karma would be appreciated.

tlscelsi
Engager

Hey Rich,

Thanks for confirming my suspicions. As a follow up question, for instance if from each of those events I extracted TWO metrics, would that then count as 16 * 150bytes?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Any given event in a metrics index can contain a single metric.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...