Hi All,
Running Splunk 6 and using the Universal Forwarder (Version 6.0.182611) to forward IIS to splunk. Indexing is working correctly however we have had license breaches in the last 2 days since adding the IIS source where I believe we should have had spare capacity.
Question:
The size of the log files on the server (~120mb yesterday) doesn't seem to match the indexing size even closely. Running the search for yesterday (Only 1 IIS server currently so only 1 sourcetype=iis):
sourcetype=iis | eval size=len(_raw) | stats sum(size)
This search shows it at around around 700mb. Is there a trick to IIS and log usage? How would a 120mb log file consume so much more that its actual size?
This question seems similar to http://answers.splunk.com/answers/129381/iis-log-over-my-licensing which no one has responded.
Any tips, clues, links etc....
Brad
... View more