Splunk Enterprise

Reaching the license limit- What can we do to not breach the limit?

danielbb
Motivator

We are quite close to reach the license limit, data wise, about 2 TBs off the 20 or so TBs allowed.

What can we do to insure that we don't breach the license limit?

Labels (1)
Tags (1)
0 Karma

danielbb
Motivator

We would like to have an analysis and identification of the increase in the data. Would the MC do it?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Maybe.  It depends on what you're looking for.  Try the MC.  If it doesn't fill your needs then ask a new question.

---
If this reply helps you, Karma would be appreciated.

richgalloway
SplunkTrust
SplunkTrust

Exceeding your license limit once is not a problem.  It only becomes a problem if you exceed the limit 5 times within 30 days.

To avoid going over your limit, turn off some data inputs until after midnight.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...