Splunk Enterprise Security

Splunk Enterprise Security: How does ES determine license consumption?

danielbb
Motivator

We wonder how ES determines the license consumption.
After all, sometimes only few events from a certain index are classified as ES events by the TAs.

1 Solution

DavidHourani
Super Champion

Hi @danielbb,

ES itself doesn't have it's own license consumption model.

Licensing depends on the DM's you are using and which indexes they are including. Total volume used by ES is the total volume of indexes used in it.

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @danielbb,

ES itself doesn't have it's own license consumption model.

Licensing depends on the DM's you are using and which indexes they are including. Total volume used by ES is the total volume of indexes used in it.

Cheers,
David

danielbb
Motivator

Ok, but if the index used by the DM is only partially used, let's say, only 10% of the index is needed, how does it work?

0 Karma

DavidHourani
Super Champion

Yeah that can be an issue especially since most of the time you end up paying an ES license equal to your core license because it's assumed that "most of the volume will end up in ES anyway".

Best way to handle this problem is to talk to the sales rep and see at what point your "license" will cost you more. As it is now, the only thing the license does it allow you to get the ES installer and install it, doesn't limit your use of the application.

0 Karma

danielbb
Motivator

Thank you @DavidHourani.

0 Karma

DavidHourani
Super Champion

You're welcome @danielbb glad I could help 🙂

0 Karma

richgalloway
SplunkTrust
SplunkTrust

ES does not measure its license consumption.

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...