Installation

enterprise licensing for huge static local data

nina15
Communicator

Does splunk need enterprise licensing for local data resource with a static but huge size (i.e. ~90GB) ?

Tags (1)
0 Karma

nina15
Communicator

you have about 90GB that spunk has
never seen before

great way of clarification... thanks!

0 Karma

kdenton
Path Finder

Ayn is correct,

Think of a summary index as an index of data that has already been ingested.

So if I think about what you are doing above, you have about 90GB that spunk has never seen before, so with out an enterprise license you would be limited to 500MB per day.

nina15
Communicator

and then what the following means??

Note: Summary indexing volume is not
counted against your license.

source: splunk-license

0 Karma

Ayn
Legend

It means that any summary indexing you are doing will not be counted when the amount of indexed data is retrieved. If you don't know what summary indexing is, here is some information on it in the docs: docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usesummaryindexing

0 Karma

kdenton
Path Finder

Slunk license is based on the amount you ingest in a 24 hour period, you get 500 mb per 24 hour per period.

Two solutions

One: chop the data into smaller chunks of 500 mb per day. Spunk will work just fine.

Two: License spline but for 90 GB would be a bit costly.

nina15
Communicator

feeding will reach the maximum limit as well, right?
i got the yellow warning saying it has exceeded..
I read in licensing info that if the warning exists it will be counted as a license violation, resulting to blocking of testing version of Splunk...

0 Karma

Ayn
Legend

Three: Feed it all to Splunk as lookups! 😄

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...