<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to determine daily license usage in GB? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18081#M2428</link>
    <description>&lt;P&gt;Thank You!  I wasted quite a bit of time until I ran across&lt;BR /&gt;
your comment.  I ended up with:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*license_usage* type=RolloverSummary  | bucket _time span=1d | eval MB_vol=b/1024/1024 | timechart span=1d sum(MB_vol) by pool
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 07 Feb 2013 21:23:25 GMT</pubDate>
    <dc:creator>ualbanytech</dc:creator>
    <dc:date>2013-02-07T21:23:25Z</dc:date>
    <item>
      <title>How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18074#M2421</link>
      <description>&lt;P&gt;What's a search I can run to quickly see my daily license usage in GB?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2010 23:52:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18074#M2421</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-07-21T23:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18075#M2422</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;index=_internal todaysbytesindexed startdaysago=30 | eval GB_Indexed = todaysBytesIndexed/1024/1024/1024 | timechart span=1d avg(GB_Indexed)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This search is included in the Search App's set of bundled indexing-related searches as of version 4.1.4.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2010 23:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18075#M2422</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-07-21T23:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18076#M2423</link>
      <description>&lt;P&gt;Also, you can find on &lt;A href="http://www.splunkbase.com" rel="nofollow"&gt;SplunkBase&lt;/A&gt; the &lt;A href="http://www.splunkbase.com/apps/All/4.x/App/app%3aSplunk+License+Usage" rel="nofollow"&gt;Splunk License Usage Apps&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;In addition to the daily license usage, this Splunk Apps provides a dashboard of your Splunk license usage total over the past 24 hours as well as usage by host, source, and sourcetype. It contains timecharts to help you understand usage over time and see usage spikes as well as pie charts to help you to figure out which log files, sourcetypes, and hosts Splunk is indexing the most data from.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2010 00:13:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18076#M2423</guid>
      <dc:creator>Lionel</dc:creator>
      <dc:date>2010-07-22T00:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18077#M2424</link>
      <description>&lt;P&gt;A simple way to do this, adapting @wolverine's search above:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal todaysbytesindexed startdaysago=30 | eval MB_Indexed = todaysBytesIndexed/1024/1024 | stats sum(MB_Indexed) by date_mday,date_month,date_year
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will provide a table of usage over time, broken out in a table by date&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2010 05:47:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18077#M2424</guid>
      <dc:creator>Justin_Grant</dc:creator>
      <dc:date>2010-08-11T05:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18078#M2425</link>
      <description>&lt;P&gt;This has been answered several times, but here are searches I use.&lt;/P&gt;

&lt;P&gt;daily total by GB:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="_internal" source="*metrics.log" per_index_thruput | eval GB=kb/(1024*1024) | timechart span=1d sum(GB) | convert ctime(_time) as timestamp
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;highest-usage indexes:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="_internal" source="*metrics.log" per_index_thruput | eval GB=kb/(1024*1024) | stats sum(GB) as total by series date_mday | sort total | fields + date_mday,series,total | reverse
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 31 Dec 2010 00:03:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18078#M2425</guid>
      <dc:creator>tedder</dc:creator>
      <dc:date>2010-12-31T00:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18079#M2426</link>
      <description>&lt;P&gt;Similar to Tedder's, here are the searches I always use to see a nice graphical view of indexing in Advanced Charting view, last 24 hours:&lt;/P&gt;

&lt;P&gt;Today's indexing by sourcetype:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="_internal" source="*metrics.log" per_sourcetype_thruput | eval MB=kb/1024 | timechart span=10m sum(MB) by series
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Today's indexing by index:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="_internal" source="*metrics.log" per_index_thruput | eval MB=kb/1024 | timechart span=10m sum(MB) by series
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If certain sourcetypes/indexes are too big, you can use the Y axis log-scale option, or exclude them, such as Today's non-internal indexing by sourcetype:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="_internal" source="*metrics.log" per_sourcetype_thruput NOT series=splunkd NOT series=stash | eval MB=kb/1024 | timechart span=10m sum(MB) by series
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 May 2011 15:06:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18079#M2426</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2011-05-20T15:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18080#M2427</link>
      <description>&lt;P&gt;Beware, in 4.2 and in 4.3, the &lt;STRONG&gt;license metrics log files format changed&lt;/STRONG&gt;.&lt;BR /&gt;
please update your searches according to this guide :&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume"&gt;http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2012 04:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18080#M2427</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-03-01T04:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18081#M2428</link>
      <description>&lt;P&gt;Thank You!  I wasted quite a bit of time until I ran across&lt;BR /&gt;
your comment.  I ended up with:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*license_usage* type=RolloverSummary  | bucket _time span=1d | eval MB_vol=b/1024/1024 | timechart span=1d sum(MB_vol) by pool
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 07 Feb 2013 21:23:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18081#M2428</guid>
      <dc:creator>ualbanytech</dc:creator>
      <dc:date>2013-02-07T21:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18082#M2429</link>
      <description>&lt;P&gt;From a License Server version 4.3 and newer:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;By POOL:&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;index=_internal source=&lt;EM&gt;license_usage.log&lt;/EM&gt;&lt;BR /&gt;
&lt;STRONG&gt;type=RolloverSummary&lt;/STRONG&gt; | eval GB=b/1024/1024/1024 | timechart span=1d sum(GB) by pool limit=20&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;By Sourcetype (or Host or Source):&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;index=_internal source=&lt;EM&gt;license_usage.log&lt;/EM&gt;&lt;BR /&gt;
&lt;STRONG&gt;type=Usage&lt;/STRONG&gt; | eval GB=b/1024/1024/1024 | timechart span=1d sum(GB) by st limit=20&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18082#M2429</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2020-09-28T15:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18083#M2430</link>
      <description>&lt;P&gt;After running your query, I am getting blank for few of the dates . I am getting completely blank rows for few of the dates. Please help why is this coming as blank. It means there is no event appears in the license log for these dates.&lt;/P&gt;

&lt;P&gt;Please help !!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2015 18:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18083#M2430</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2015-08-26T18:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18084#M2431</link>
      <description>&lt;P&gt;Note for the record that this search has not worked since v5 or so.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 20:31:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/18084#M2431</guid>
      <dc:creator>hrottenberg_spl</dc:creator>
      <dc:date>2019-12-04T20:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to determine daily license usage in GB?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/657548#M111296</link>
      <description>&lt;P&gt;This query can be further modified into this:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="_internal" source="*metrics.log" per_index_thruput series=* NOT ingest_pipe=*
|stats sum(kb) as kb values(host) as host by series&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;however this query will also show the amount of KBs being logged into indexes via summary indexing (sourcetype=stash), which is supposed to be not charged.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Hence, I would prefer this query:&lt;BR /&gt;index=_internal type=usage idx IN (*) source="*license_usage.log" NOT (h="" OR h=" ")&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 07:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-determine-daily-license-usage-in-GB/m-p/657548#M111296</guid>
      <dc:creator>jokertothequinn</dc:creator>
      <dc:date>2023-09-14T07:22:26Z</dc:date>
    </item>
  </channel>
</rss>

