<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic License server don't show 30 days license usage in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/License-server-don-t-show-30-days-license-usage/m-p/580956#M11157</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;in my deploy server, that act as a LM,&amp;nbsp; i cannot see Licese Usage Report for 30-day period.&lt;/P&gt;&lt;P&gt;It always shows "No results found". For the "today" report i can see data.&lt;/P&gt;&lt;P&gt;Looking at&amp;nbsp;../var/splunk folder i can see the license_usage.log file but there's no&lt;/P&gt;&lt;P&gt;&lt;EM&gt;type=Rollover_Summary &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;inside.&lt;/P&gt;&lt;P&gt;There's only&lt;EM&gt; type=Usage.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Could you help me check this issue?&lt;BR /&gt;Thanks a log&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jan 2022 14:18:06 GMT</pubDate>
    <dc:creator>fabiolabruzzo</dc:creator>
    <dc:date>2022-01-13T14:18:06Z</dc:date>
    <item>
      <title>License server don't show 30 days license usage</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/License-server-don-t-show-30-days-license-usage/m-p/580956#M11157</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;in my deploy server, that act as a LM,&amp;nbsp; i cannot see Licese Usage Report for 30-day period.&lt;/P&gt;&lt;P&gt;It always shows "No results found". For the "today" report i can see data.&lt;/P&gt;&lt;P&gt;Looking at&amp;nbsp;../var/splunk folder i can see the license_usage.log file but there's no&lt;/P&gt;&lt;P&gt;&lt;EM&gt;type=Rollover_Summary &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;inside.&lt;/P&gt;&lt;P&gt;There's only&lt;EM&gt; type=Usage.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Could you help me check this issue?&lt;BR /&gt;Thanks a log&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 14:18:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/License-server-don-t-show-30-days-license-usage/m-p/580956#M11157</guid>
      <dc:creator>fabiolabruzzo</dc:creator>
      <dc:date>2022-01-13T14:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: License server don't show 30 days license usage</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/License-server-don-t-show-30-days-license-usage/m-p/581001#M11159</link>
      <description>&lt;P&gt;I've had this same issue. I was able to resolve it by ensuring that my Deployment Server is set to a "search head" along with being a deployment server.&lt;/P&gt;&lt;P&gt;Are you receiving other _internal logs from your deployment server?&lt;/P&gt;&lt;P&gt;Run this query on your search head:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal source=*license_usage.log type="RolloverSummary" earliest=-30d@d | eval _time=_time - 43200 | bin _time span=1d | stats latest(b) AS b by slave, pool, _time | timechart span=1d sum(b) AS "volume" fixedrange=false | join type=outer _time [search index=_internal source=*license_usage.log type="RolloverSummary" earliest=-30d@d | eval _time=_time - 43200 | bin _time span=1d | stats latest(stacksz) AS "stack size" by _time] | fields - _timediff | foreach * [eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;=round('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'/1024/1024/1024, 3)]&lt;/LI-CODE&gt;&lt;P&gt;If this search works then that means your Deployment Server is not configured to search within it's own logs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 18:09:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/License-server-don-t-show-30-days-license-usage/m-p/581001#M11159</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-01-13T18:09:36Z</dc:date>
    </item>
  </channel>
</rss>

