|
In the latest versions of Splunk, summary indexing does not deduct from the licensed indexing capacity. How does Splunk determine if data is summary data? Is it through use of the summary search commands (e.g. sistats, sichart, collect)? Does it exclude indexes prefaced with 'summary?' Do you have to check the "Enable Summary Indexing" box when scheduling the summary search? |
|
Only data that is populated through a summary search command is exempt from the daily licensing volume. For clarity the search commands are sitop, sirare, sistats, sichart, sitimechart and collect.
(15 Oct '10, 22:16)
hulahoop ♦
Also, this is only true for versions 4.0.10 / 4.1 and later. In earlier versions, summary indexing counted towards your license just like any other input.
(16 Oct '10, 01:05)
Lowell ♦
|
|
Generally, summary index data is not counted against license volume. More specifically, the summary indexing command |