hello ...
we have installed splunk 6.0 successfully , and now we are in the testing phase to see if it is compatible with our servers.
after integrating ONLY the File server (shared folder) the daily limit 500MB has exceeded by 300%!!!
My question is how is it calculated?
does it depend on the size of the logs stored on the Splunk server or what exactly
Now the server is down because we got 3 warring and we cannot proceed with the testing.
The daily limit is determined by the amount of log files that you consume into Splunk. See http://docs.splunk.com/Documentation/Splunk/latest/Admin/HowSplunklicensingworks
for a more thorough explanation. You may also want to install a Dev license for your testing. https://www.splunk.com/index.php?module=roles&func=showloginform&prompt=1&redirecturl=http://dev.spl...