Hi,
Does the lastChanceIndex consume license? and is there a way to find out how much?
Hi @echojosh
The lastChanceIndex in Splunk does consume license, just like any other index storing data ingested into Splunk. Data sent to lastChanceIndex usually results from misconfigured inputs or when events can't otherwise be routed to a target index, so that data contributes to daily license usage.
Hi @echojosh
The lastChanceIndex does consume license in Splunk. It counts toward your daily indexing volume limit just like any other index.
You can use the following search to see the usage, updating the index name accordingly.
index=_internal source=*license_usage.log type="Usage"
| eval GB=b/1024/1024/1024
| search idx="lastChangeIndex"
| stats sum(GB) as "GB Used" by idx
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Thanks for the GPT but that does not work.
You're getting an empty result because the lastChanceIndex may not have configured.
If lastChanceIndex is not configured, Splunk will drop the data and log a warning like - "Dropping them as lastChanceIndex setting in indexes.conf is not configured.So far received events from 1 missing index(es)"
Did you got any warning message like this?
Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
1. Well, that was not GPT.
2. If you just copy-pasted... well, it's on you.
3. If you properly adjusted and got no results, that means you have no events in that index.