Installation

Are there best practices for controlling my daily license quota used per pool?

kgraw21
New Member

I am a newbie and just getting started. I'm only pulling local data from the Splunk Server. I do have a few apps installed for Active directory and Utilization Monitor. I have a 5GB limit limit and my daily usage is already at 2.267GB of usage. What happens when I set up forwarders for at least 60 additional servers? Is my license big enough? Is there a best practice documentation for newbies?

Labels (2)
0 Karma

maciep
Champion

It all depends on the data you want to bring in. On those 60 forwarders, do you know what logs you're looking to ingest? Can you do some manual calculations to determine how much per day that would be. Will each forwarder report the same type of data? Meaning, can you install on one and extrapolate from there?

Are you bringing in anything today that you don't need? Maybe something being ingested by default by the apps you installed?

The documentation is worth a read. But at a high-level, if you go over your license for a day then you get a warning. If you get 5 warnings in a rolling 30 day period then you're in violation. At that point, you won't be able to search your data, however it will still be indexed. You would need to request a reset key to remove the warnings and start - something you'd get from your sales contact or support.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...