Splunk Cloud Platform

How to control DDAS license

prashanthan1987
Explorer

I am seeking recommendations on how to better control DDAS license consumption by identifying log patterns that are unnecessary and eliminating them before they reach the indexing layer, or alternatively moving older/low‑value data to archival storage so that it does not count toward DDAS usage.

We have already begun exploring several approaches—including leveraging summary indexes, routing selected logs directly to S3, and filtering out unwanted data at the ingestion layer. However, we are looking for a more effective strategy that allows us to reduce DDAS usage while still retaining the original log structure and maximum field availability where required.

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Moving old data won't change anything. Your license is counted on ingest, at the moment the data is written to the index, to be precise.

And it's up to you to know which data you need and which you don't you can't eat the cake and have the cake at the same time.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...