QuestionQ17

Licensing and Crash Problems

A customer has defined their environment scope:

  • Data ingestion of 600 GB/day
  • 1 standalone search head
  • 3 clustered indexers

They have purchased an ingest license for 900 GB/day. What is the simplest way to configure the license according to Splunk best practices?

  • A Add the license and configure three pools with a custom pool size of 200 GB each.
  • B Add the license and configure three pools with a custom pool size of 300 GB each.
  • C Add the license and configure a single pool with a custom pool size of 200 GB.
  • D Add the license and use the default pool size of 900 GB.
Explanation

A Splunk Enterprise license specifies the daily volume of data that can be indexed. Its default Enterprise license pool is available to any connected license peer, so leaving the default pool at 900 GB/day provides sufficient shared capacity for 600 GB/day of ingestion without unnecessary per-indexer pool allocations.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!