In the latest versions of Splunk, summary indexing does not deduct from the licensed indexing capacity. How does Splunk determine if data is summary data? Is it through use of the summary search commands (e.g. sistats, sichart, collect)? Does it exclude indexes prefaced with 'summary?' Do you have to check the "Enable Summary Indexing" box when scheduling the summary search?
Only data that is populated through a summary search command is exempt from the daily licensing volume.
Generally, summary index data is not counted against license volume. More specifically, the summary indexing command collect
generates data with the SI stash
sourcetype and this is not counted against license. Using the si-
commands in other ways, or using collect
and overriding the sourcetype will count against your license.
Generally, summary index data is not counted against license volume. More specifically, the summary indexing command collect
generates data with the SI stash
sourcetype and this is not counted against license. Using the si-
commands in other ways, or using collect
and overriding the sourcetype will count against your license.
Only data that is populated through a summary search command is exempt from the daily licensing volume.
Also, this is only true for versions 4.0.10 / 4.1 and later. In earlier versions, summary indexing counted towards your license just like any other input.
For clarity the search commands are sitop, sirare, sistats, sichart, sitimechart and collect.