Hi Team,
I need help on below scenario:
We have master-slave architecture in Splunk: 1 master indexer and 3 slave indexers. We have 5 GB of license. From a few days, it is noticed that Splunk _internal logs (splunkd.log,metrics.log,mongod.logs) are consuming the license. But according to the answers available here, Splunk should not consider the _internal data in license usage. Please find below links for the same:
https://answers.splunk.com/answers/302907/does-the-indexing-of-splunk-internal-logs-such-as.html
Need some help to fix the above issue.
Thanks & Regards, kalyani Landge
... View more