Installation

enterprise licensing for huge static local data

nina15
Communicator

Does splunk need enterprise licensing for local data resource with a static but huge size (i.e. ~90GB) ?

Tags (1)
0 Karma

nina15
Communicator

you have about 90GB that spunk has
never seen before

great way of clarification... thanks!

0 Karma

kdenton
Path Finder

Ayn is correct,

Think of a summary index as an index of data that has already been ingested.

So if I think about what you are doing above, you have about 90GB that spunk has never seen before, so with out an enterprise license you would be limited to 500MB per day.

nina15
Communicator

and then what the following means??

Note: Summary indexing volume is not
counted against your license.

source: splunk-license

0 Karma

Ayn
Legend

It means that any summary indexing you are doing will not be counted when the amount of indexed data is retrieved. If you don't know what summary indexing is, here is some information on it in the docs: docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usesummaryindexing

0 Karma

kdenton
Path Finder

Slunk license is based on the amount you ingest in a 24 hour period, you get 500 mb per 24 hour per period.

Two solutions

One: chop the data into smaller chunks of 500 mb per day. Spunk will work just fine.

Two: License spline but for 90 GB would be a bit costly.

nina15
Communicator

feeding will reach the maximum limit as well, right?
i got the yellow warning saying it has exceeded..
I read in licensing info that if the warning exists it will be counted as a license violation, resulting to blocking of testing version of Splunk...

0 Karma

Ayn
Legend

Three: Feed it all to Splunk as lookups! 😄

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...