The reason i ask this is because i recently installed UFs on one of my DC and daily license has gone up by 15-20 gb but i dont see that much data coming into it.
events ike 4624 have the line count as 63 (seen from the interesting field column) and i read somewhere that splunk license count is based on line count field, which means 1 event of 4624 is counted as 63 events because of line count.
↧