Splunk Cloud Platform

Sudden increase in license usage after the "Anaconda' upgrade

ptur
Path Finder

Our cloud instance was upgraded 3 days ago, since then the log volume increased by about 20% - we're logging same amount of data as for the past 3+ years - have anyone had to deal with similar issue? 

 

I looked at indexes - they all seem to increased logging proportionally, which leads me to believe it a change in the current version...that made it "less efficient" in this respect...

 

Thanks!

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check number of logs across days. Check event size across says...

0 Karma

Stefanie
Builder

Is there a chance that data is being duplicated? Run a search like index=_internal source=*license_usage.log for data up to 3 days ago. 

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...