Security

License will be violated for initial indexing only

stanwin
Contributor

Hi

Have a peculiar problem.

WIth a 2GB enterprise license , I want to index 4GB of data initially. Post that SPLUNK will only consume the updates in the logs which is determined around >300MB

I dont have a particular way to split the load because the total number of log files in folder is approx 100,000 & Naming convention is same for all .

Was wondering if anyone has any past experience or approaches for this type of scenario.

Note that 4GB is the total size of the logs. Even when rollout/application restart happens, files are retained for 15 days & that maybe more than 2 GB.

Tags (1)
0 Karma

aholzel
Communicator

If it is just a one time 4GB data input (to get up and running so to speak) there is no problem, sure you get a license violation but as long as it is just a one time event there is no real problem. You can have 5 violations in a 30 day window after that you will have a problem, you can't search your data anymore and need to get a reset key.

juvetm
Communicator

hi
you can not have 2GB enterprise license and you want to index 4GB of data this is License violation if it is summary index no thing will happen to it but as it concern indexing 4gb data this really licence violaton

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...