<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decode indexer name hashes (GUID)  from license_usage.log in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43081#M2167</link>
    <description>&lt;P&gt;Remember you can just browse &lt;A href="https://splunkinstance:8089"&gt;https://splunkinstance:8089&lt;/A&gt; with a browser, and look for interesting things.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Apr 2013 15:18:50 GMT</pubDate>
    <dc:creator>Jason</dc:creator>
    <dc:date>2013-04-29T15:18:50Z</dc:date>
    <item>
      <title>Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43071#M2157</link>
      <description>&lt;P&gt;In license_usage.log the indexers appears as a kind of hash value (i=...):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;01-02-2012 16:56:16.516 +0100 INFO  LicenseUsage - type=Usage s="udp:514" st="cisco_asa" h="172.16.22.7" o="" i="821C72AB-3C16-4124-B278-6C02F448DC22" pool="mypool" b=17906 poolsz=100000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For reporting I want to look up the real names of the indexers. Is there an internal lookup table for doing this?&lt;/P&gt;

&lt;P&gt;Update: This field is the GUID of the system. But how to lookup the system name?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2012 16:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43071#M2157</guid>
      <dc:creator>Spelunke</dc:creator>
      <dc:date>2012-01-02T16:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43072#M2158</link>
      <description>&lt;P&gt;To answer my own question:&lt;/P&gt;

&lt;P&gt;According to a Splunk guy it’s not possible to lookup the GUID internally.&lt;/P&gt;

&lt;P&gt;I build a external lookup table to do that.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Feb 2012 11:07:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43072#M2158</guid>
      <dc:creator>Spelunke</dc:creator>
      <dc:date>2012-02-25T11:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43073#M2159</link>
      <description>&lt;P&gt;| rest /services/configs/conf-server/general&lt;/P&gt;

&lt;P&gt;If you want to look for a specific server by its hostname, you can add splunk_server=&amp;lt;name&amp;gt; to the end of that search.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2013 16:43:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43073#M2159</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-02-05T16:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43074#M2160</link>
      <description>&lt;P&gt;I'm sorry, but this is a lousy way to present information back to administrators during a rolling restart.  You can't ping based on an indexer's Guid, you can't ssh to a Guid, you can't use the Guid in your web browser, so if there is a problem with an indexer in the cluster resolve it yourself.  I brought this issue up with Splunk Professional Services and our sales engineers.  I guess Splunk wanted to add back a little of the SH they have been taking out of IT.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2013 19:09:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43074#M2160</guid>
      <dc:creator>gmti</dc:creator>
      <dc:date>2013-04-10T19:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43075#M2161</link>
      <description>&lt;P&gt;This does not display all the license slaves, it seems.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2013 10:14:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43075#M2161</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2013-04-29T10:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43076#M2162</link>
      <description>&lt;P&gt;This feedback would be better off as a Enhancement Request to Splunk (a P4 to Splunk Support), rather than on here where they may not see it.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2013 10:15:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43076#M2162</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2013-04-29T10:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43077#M2163</link>
      <description>&lt;P&gt;Yes, you can look up the hostname of the licenser slave in 4.3+ via the following:&lt;/P&gt;

&lt;P&gt;Be sure to &lt;A href="http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume#Log_file_specificity_to_4.3"&gt;select a type of log in license_usage.log&lt;/A&gt; to avoid double-counting statistics.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*license_usage.log type=Usage
| join type=left i 
    [rest count=0 /services/licenser/slaves 
    | rename label as slave 
    | rename title as i 
    | table i slave]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The new "slave" field (or whatever you choose to &lt;CODE&gt;rename label&lt;/CODE&gt; as) will now appear in the results.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2013 10:20:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43077#M2163</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2013-04-29T10:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43078#M2164</link>
      <description>&lt;P&gt;It is possible with the &lt;CODE&gt;rest&lt;/CODE&gt; command, available in 4.3 onwards. See my answer.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2013 10:21:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43078#M2164</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2013-04-29T10:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43079#M2165</link>
      <description>&lt;P&gt;Clever. I'll have to remember this endpoint.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2013 13:44:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43079#M2165</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-04-29T13:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43080#M2166</link>
      <description>&lt;P&gt;No; it only polls search peers by default. I suppose you could try splunk_server=&amp;lt;license_master&amp;gt; to the rest call, but that presumes that you have access to the license master itself.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:48:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43080#M2166</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2020-09-28T13:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43081#M2167</link>
      <description>&lt;P&gt;Remember you can just browse &lt;A href="https://splunkinstance:8089"&gt;https://splunkinstance:8089&lt;/A&gt; with a browser, and look for interesting things.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2013 15:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43081#M2167</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2013-04-29T15:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43082#M2168</link>
      <description>&lt;P&gt;Provided the indexers in question are also peers of this particular search head, you can join with this REST query from any, not just the license master:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;rest /services/search/distributed/peers 
| table guid peerName
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 23 Feb 2015 16:37:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43082#M2168</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2015-02-23T16:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43083#M2169</link>
      <description>&lt;P&gt;don't forget the | before rest.&lt;BR /&gt;
&lt;CODE&gt;|rest /services/search/distributed/peers &lt;BR /&gt;
 | table guid peerName&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2017 22:24:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43083#M2169</guid>
      <dc:creator>rphillips_splk</dc:creator>
      <dc:date>2017-08-14T22:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43084#M2170</link>
      <description>&lt;P&gt;Assuming Splunk 6.x or better:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rest /services/cluster/config 
| fields splunk_server guid
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 25 May 2018 13:46:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/43084#M2170</guid>
      <dc:creator>mlf</dc:creator>
      <dc:date>2018-05-25T13:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Decode indexer name hashes (GUID)  from license_usage.log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/565043#M75034</link>
      <description>&lt;P&gt;For Splunk 7 &amp;amp; 8 at least:&lt;/P&gt;&lt;P&gt;To get the daily ingestion per indexer with the hostname rather than the GUID following your time range picker selection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_telemetry source=*license_usage_summary.log* type="RolloverSummary"
| join type=inner slave [ | rest /servicesNS/-/-/search/distributed/peers splunk_server=local | table guid host | rename guid AS slave ]
| search host=*PATTERN*
| timechart span=1d eval(round(latest(b) / 1024 / 1024 / 1024, 3)) AS sizeGB BY host useother=f&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Replace PATTERN by your indexers hostname convention.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 11:37:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Decode-indexer-name-hashes-GUID-from-license-usage-log/m-p/565043#M75034</guid>
      <dc:creator>cyvi01</dc:creator>
      <dc:date>2021-08-27T11:37:32Z</dc:date>
    </item>
  </channel>
</rss>

