Installation

SEDCMD and license volume

southeringtonp
Motivator

When using SEDCMD to strip data from an event, does the entire event count toward license usage, or only the portion of the event that is actually retained?


For example, if I have an event like:

Field1=Something|Field2=SomethingReally....Long|Field3=SomethingElse

And apply:

SEDCMD=s/Field2=[^|]+//g

Will the contents of Field2 count against the license cap?

Tags (2)
1 Solution

twinspop
Influencer

gkanapathy has previously stated that SEDCMD substitutions happen before license accounting. So, no, the contents of Field2 should not be included in your license usage.

View solution in original post

twinspop
Influencer

gkanapathy has previously stated that SEDCMD substitutions happen before license accounting. So, no, the contents of Field2 should not be included in your license usage.

southeringtonp
Motivator

Ah, good catch! I looked for the previous answer but missed it somehow.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...