Installation

enterprise licensing for huge static local data

nina15
Communicator

Does splunk need enterprise licensing for local data resource with a static but huge size (i.e. ~90GB) ?

Tags (1)
0 Karma

nina15
Communicator

you have about 90GB that spunk has
never seen before

great way of clarification... thanks!

0 Karma

kdenton
Path Finder

Ayn is correct,

Think of a summary index as an index of data that has already been ingested.

So if I think about what you are doing above, you have about 90GB that spunk has never seen before, so with out an enterprise license you would be limited to 500MB per day.

nina15
Communicator

and then what the following means??

Note: Summary indexing volume is not
counted against your license.

source: splunk-license

0 Karma

Ayn
Legend

It means that any summary indexing you are doing will not be counted when the amount of indexed data is retrieved. If you don't know what summary indexing is, here is some information on it in the docs: docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usesummaryindexing

0 Karma

kdenton
Path Finder

Slunk license is based on the amount you ingest in a 24 hour period, you get 500 mb per 24 hour per period.

Two solutions

One: chop the data into smaller chunks of 500 mb per day. Spunk will work just fine.

Two: License spline but for 90 GB would be a bit costly.

nina15
Communicator

feeding will reach the maximum limit as well, right?
i got the yellow warning saying it has exceeded..
I read in licensing info that if the warning exists it will be counted as a license violation, resulting to blocking of testing version of Splunk...

0 Karma

Ayn
Legend

Three: Feed it all to Splunk as lookups! 😄

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...