Hi,
Because of license renew/upgrade: is there any way to report/estimate the license volume processed by Enterprise Security?
Regards,
István
Hi ikulcsar,
This is not really related to Enterprise Security, but just a basic Splunk question. License usage is calculated the same with or without ES, it is based on the amount raw data being indexed.
Read the docs about the LURV here http://docs.splunk.com/Documentation/Splunk/latest/Admin/LicenseUsageReportViewexamples
Hope this helps ...
cheers, MuS
Hi ikulcsar,
This is not really related to Enterprise Security, but just a basic Splunk question. License usage is calculated the same with or without ES, it is based on the amount raw data being indexed.
Read the docs about the LURV here http://docs.splunk.com/Documentation/Splunk/latest/Admin/LicenseUsageReportViewexamples
Hope this helps ...
cheers, MuS
Hi,
Thx for the reply. I familiar with the Splunk Enterprise licensing.
We have security related sources along with non-security ones. And there are some partial security and non -security sources.
After all, we don't wanna buy ES license for all the Splunk Enterprise license, somehow we have to measure the log volume processed by ES.
Based on what I've been up to today, I guess there is no built-in solution for this, but maybe someone can help, so I asked.
Regards,
István
Well, you can have a look at the license usage by sourcetype based on the LURV to get the numbers.
But you will most likely have two problems:
Just my 2 cents 😉
cheers, MuS
Yep, thx.
That's what I was afraid to do. I have to find out which source is ES relevant, which is not...
Thanx for your time and help.
Regards,
István