Splunk Enterprise

Premium apps licensing vs. Splunk Enterprise licensing

PickleRick
SplunkTrust
SplunkTrust

As far as I know, the size of the ITSI or ES license a customer buys should be equal to the basic Splunk Enterprise license.

But what if a customer wants to have a single Splunk Enterprise installation dedicated to different uses? For example, a customer buys a 3TB license of which it expects to use 1TB for security related events, 1TB for serivice monitoring and the rest for other uses, mostly business intelligence. Pricing ITSI and ES for 3TB each seems a bit expensive.

Does license pool help here in any way? But even if so, the license pool is allocated per indexer, not per index if I remember correctly. So that would mean the necessity to install separate indexer clusters for each of those uses.

Labels (1)
Tags (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

I have understood this, that you must have an equal license for core + es + ITSI for those indexers which have used data. So basically you could have separate license pool if you have also a separate indexers for ITSI and ES. And if this is not enough you could set up totally different environment which has own LM which have only those licences and another LM which have licenses for all other stuff.

r. Ismo

PickleRick
SplunkTrust
SplunkTrust

Yeah, that's pretty much what I understand myself.

So you need to separate the workload between different "subenvironments". You can't have - within the same, uniformly licensed environment - for example, different set of indexes for ops monitoring, different set for security and so on. If it's within the same environment, you have to license the whole size.

A bit sad, actually.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...