Module 3 - Licensing Splunk Flashcards
License types
Enterprise trail - valid for 60 days. Up to 500mb logs a day
Enterprise
Free license - disables alerts, schedule searches, authentication, clustering, distributed search, forwarding to non splunk servers, summarization
Forwarder license
Ingest pricing
Based in data volumes
Traditional method
Monitored in MC AND Settings > Licensing
Workload pricing
Based on compute capacity
Monitored in MC (vCPU) or cloud monitoring console (for SVCs)
Daily quota includes
Data from all sources that is indexed
Events - measured as data (full size)
Metrics - first 150 bytes per metric event
Daily quota does not include
Replicated data (index clusters)
Summary indexes
Internal logs: _internal, _audit, indexes
Components of the index: metadata, tsidx, etc
License requirements by server role and data
Search heads, deployments servers require license even if not ingesting data
Indexers need license to determine amount of allowed ingested data
Licenses folder location
SPLUNK_HOME/etc/licenses
Add license from CLI
Splunk add license <key></key>
Multiple licenses behaviour
Multiple licenses stacked
All instances collectively share stack entitlement
License pooling
Licenses can be subdivided and assigned to indexer groups (multi tenant scenario)
Most common single pool with shared entitlement
Warnings and violations per pool
License alerts
Occurs when indexing exceeds the allocated daily quota in a pool
View from WebUI > Messages
Cleared at midnight when daily allocation is reset; may result in a Warning
License warnings
Occurs if an alert is triggered and license capacity is not increased by midnight
Occurs only once per day
License violations
Occur after 5 warnings in a rolling 30 day period
Does not affect indexing or searches
Searches are disabled for licenses < 100 GB/day with 45 warnings in a rolling 60-day period
Require reset key from splunk
Monitoring console
On prem and cloud (CMC)
Provides vCPU / SVC usage across workloads
– By search type, indexes, and source types, etc
Splunk app for chargeback
On prem and cloud
Provides Search Resource Usage
(SRU) across business units – 1 SRU ~= 1 SVC
Provides forecasts using Splunk Machine Learning