How Splunk Enterprise licensing works
When data is sent to the Splunk platform, that data is indexed and stored on disk. Part of the indexing process is to measure the volume of data being ingested, and report that volume to the license master for license volume tracking.
How data is measured
When ingesting event data, the measured data volume is based on the raw data that is placed into the indexing pipeline. It is not based on the amount of compressed data that is written to disk. Because the data is measured at the indexing pipeline, data that is filtered and dropped prior to indexing does not count against the license volume quota.
When ingesting metrics data, each metric event is measured by volume like event data. However, the per-event size measurement is capped at 150 bytes. Metric events that exceed 150 bytes are recorded as only 150 bytes. Metrics data draws from the same license quota as event data.
Data that is not measured
The Splunk software troubleshooting and internal communications logs that are indexed into the internal indexes such as
_introspection do not count against your license volume quota.
The use of summary indexing and metric rollup summaries do not count against your license volume quota.
What happens if I exceed my license volume?
License warnings occur when you exceed the indexing volume allowed for your license. The indexing volume is measured daily from midnight to midnight using the system clock on the license master. See About license violations.
License types and license management
There are multiple types of Splunk software licenses available, see Types of Splunk licenses.
To learn about Splunk software license management, see Allocate license volume.
About update checker data
Types of Splunk software licenses
This documentation applies to the following versions of Splunk® Enterprise: 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10