Monitoring Splunk

License/Indexing question

jfoote9888
New Member

If we are licensed for 200 GB a day and we send 100 GB of raw data. Is it how much we send Splunk or how much we index with Splunk that counts against our daily license?

Tags (1)
0 Karma

pruthvikrishnap
Contributor
0 Karma

somesoni2
Revered Legend

It is based on the amount of raw external data that the indexer ingests into its indexing pipeline, after any filtering. It is not based on the amount of compressed data that gets written to disk.
Reference: https://docs.splunk.com/Documentation/Splunk/7.1.2/Admin/HowSplunklicensingworks#How_data_is_metered

ddrillic
Ultra Champion

By the amount you index.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

It's how much you index with Splunk per day.

By sending, I'm assuming you are sending data to nullQueue?

0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...