Splunk ITSI

Splunk itsi

arhaan015
New Member

Hi team,

 

I have a standalone production instance and on which splunk ITSI was running.

Daily ingestion:- 50gb

Itsi license:- 20gn

It's license got expired so my team purchased a new itsi license but when I am pushing the new licesnse, splunk is deleting the enterprise license and its throwing warning license exceed

MY QUESTIONS ARE :-

1) HOW ITSI LICENSE IS CALCULATED?

2) STEPS TO CREATE A STACK OF LICENSE ON SPLUNK

3) CAN I CREATE A STACK OF ENTERPRISE AND ITSI LICESNSE?

Labels (3)
Tags (2)
0 Karma

eduncan
Splunk Employee
Splunk Employee

ITSI license is calculated by the events or data written to the itsi summary index.  It doesn't charge for what is ingested in to splunk rather what ITSI is ingesting into it's engine.  You need to look at how much data is being written to the itsi_summary index each day and that is your daily ingest.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...