Installation

SEDCMD and license volume

southeringtonp
Motivator

When using SEDCMD to strip data from an event, does the entire event count toward license usage, or only the portion of the event that is actually retained?


For example, if I have an event like:

Field1=Something|Field2=SomethingReally....Long|Field3=SomethingElse

And apply:

SEDCMD=s/Field2=[^|]+//g

Will the contents of Field2 count against the license cap?

Tags (2)
1 Solution

twinspop
Influencer

gkanapathy has previously stated that SEDCMD substitutions happen before license accounting. So, no, the contents of Field2 should not be included in your license usage.

View solution in original post

twinspop
Influencer

gkanapathy has previously stated that SEDCMD substitutions happen before license accounting. So, no, the contents of Field2 should not be included in your license usage.

southeringtonp
Motivator

Ah, good catch! I looked for the previous answer but missed it somehow.

0 Karma
Get Updates on the Splunk Community!

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...