Is it required for the Splunk Enterprise Security app to match the volume of the core Splunk Enterprise license? The EULA stipulates that the Enterprise Security app is licensed per daily indexed volume.
What does 'daily indexed volume ' mean?
Example: Customer has a 500 GB Splunk Enterprise license and wants a 100 GB Splunk Enterprise Security license. In reality, he indexes 400 GB (not the full 500 yet), but for Security purposes, the scope will be limited to 100 GB. Is the customer compliant when acquiring a license Enterprise Security limited to 100 GB, or does he need to buy for the 400 GB (the actual daily indexed volume), or does he need to buy a 500 GB license (to match the core license)?
Thank you for clarifying the legal requirement (not technical)
↧