Knowledge Management

Summary indexing impact on license volume

benstraw
Splunk Employee
Splunk Employee

Will using summary indexes impact my total indexing volume and my license?

Tags (2)
2 Solutions

matt
Splunk Employee
Splunk Employee

Yes. Summary indexes do count toward your total daily indexing volume. From a license perspective summary indexes are no different than the main index. The only indexed data that does not count towards your license are Splunk's own log files.

View solution in original post

the_wolverine
Champion

As of version 4.0.10 and 4.1, summary indexed data DOES NOT count against your license!

View solution in original post

Labbemiche
Engager

https://docs.splunk.com/Documentation/Splunk/8.2.2/Knowledge/Usesummaryindexing Does summary indexing count against your license?

Summary indexing data volume is not counted against your license, even if you have multiple summary indexes.

All summarized data has a special default source type. Events summarized in a summary events index have a source type of stash. Metric data points summarized in a summary metrics index have a source type of mcollect_stash.

If you use commands like collect or mcollect to change these source types to anything other than stash (for events) or mcollect_stash (for metric data points), you will incur license usage charges for those events or metric data points.

0 Karma

the_wolverine
Champion

As of version 4.0.10 and 4.1, summary indexed data DOES NOT count against your license!

lukejadamec
Super Champion

which is true?

Do they or do they not count against volume?

0 Karma

matt
Splunk Employee
Splunk Employee

Yes. Summary indexes do count toward your total daily indexing volume. From a license perspective summary indexes are no different than the main index. The only indexed data that does not count towards your license are Splunk's own log files.

lakromani
Builder

I downvoted this post because this is old and now wrong information

0 Karma

proletariat99
Communicator

I downvoted this post because this is plain ol' wrong.

0 Karma

jtrucks
Splunk Employee
Splunk Employee

This is no longer true.

--
Jesse Trucks
Minister of Magic

lukejadamec
Super Champion

which is true?

Do they or do they not count against volume?

Get Updates on the Splunk Community!

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...

New This Month - SLO Capabilities, APM Advanced Filtering & Usage Analytics Plus ...

More for SLO Management We’re continuing to expand the built-in SLO management experience in Splunk ...

Enterprise Security Content Update (ESCU) | New Releases

In June, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...