Installation

Do multiple summary indexes affect license usage?

Paolo_Prigione
Builder

I know that since 4.1 summary indexing does not count against license anymore. However, what if I have multiple summary indexes?

According to this answer, I'd say more indexes would not affect the license, but just looked for a confirmation...

E.g.

  • summary -> the defauls summary index, residing on the search head.
  • summary1h -> stores results of scheduled aggregations having resolution of 1 hour, data kept for 1 month
  • summary1d -> stores results of scheduled aggregations having resolution of 1 day, data kept for 3 months

The last two sum-indexes would reside on a dedicate job server (with forwarding license).

Would this configuration affect license usage?

Thanks

Labels (1)
Tags (2)
1 Solution

Stephen_Sorkin
Splunk Employee
Splunk Employee

Adding more summary indexes will not affect license usage. No summary indexed data will count against the license.

View solution in original post

Stephen_Sorkin
Splunk Employee
Splunk Employee

Adding more summary indexes will not affect license usage. No summary indexed data will count against the license.

Paolo_Prigione
Builder

Thanks Stephen,
Paolo

0 Karma

aledantas2k12
Explorer

Wrong! If you overwrite the original sourcetype created by "|collect " (stash) it will count towards your licence.

0 Karma

ww9rivers
Contributor

Can Splunk please clarify? Is it true that, if sourcetype is changed to anything other than "stash", summary indexed data would count against license usage?

Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...
OSZAR »