I upgraded Splunk Enterprise to 8.1.8 from 8.0.6. I am now getting messages where 45 days are allowed over 60 days to go over the indexing limit. Looking at the indexing, the largest amount are from internal Splunk. I have a single instance.
The first three indexes are internal Splunk
The largest source is the Splunk Metrics log
And lastly, the sourcetypes splunk_metrics_log and splunkd are a major portion of indexed data
My question is, why is the internal Splunk processes counting towards my indexing?
Regards,
Scott Runyon
Hi
it shouldn't count toward your license.
What you see with this url (change localhost if needed) "http://localhost:8000/en-US/manager/search/licenseusage"
r. Ismo