Splunk Search

Index violation maximum?

alexbarron
Engager

Let's say I have a 5GB license. I understand that if I exceed 5GB in a day, I will incur a violation. The violation will most likely be only one or two GB above my license limit. What if, however, I suddenly index something significantly above my license? For example, 200GB. Is there any sort of additional restriction or punishment on this or does it just count as a standard violation like 7GB would?

Splunk continues to index all your data even if you have several violations but it seems unlikely they would index 200GB of data if your license is only 5GB. There must be some kind of maximum.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

no. once you are over for a day, it is single violation, even if it is significantly over. there is no maximum (other than limits of your system and hardware).

Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...