When a log file is brought inside the Splunk indexer after input phase it is compressed to almost 10% of its value. So if a 100Gb file is put onto indexer cluster say it gets compressed to 15 Gb, so how much indexer license will be used for the file to extract indexes from the raw data file indexer gets from forwarders? Is it 15Gb or 100Gb? Please suggest.
The data passes through the license meter before it is compressed and before the index files are created (which can be quite large).
So a 100Gb input source would use 100Gb of splunk license.
Hi @vikram_m - Glad to hear that lguinn and ddrillic were able to provide helpful feedback. Please don't forget to resolve this post by clicking "Accept" below the best answer 🙂 Thanks!
Please note that data that is eliminated during the parsing process doesn't count against the daily quota.
About the parsing phase at How to Filter Unwanted Data without adding to Splunk Daily Indexing Volume
It says -
Thank ddrillic this was helpful. 🙂
The data passes through the license meter before it is compressed and before the index files are created (which can be quite large).
So a 100Gb input source would use 100Gb of splunk license.
Thanks lguinn this was helpful.