<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic License Usage by sourcetype in 6.6 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/License-Usage-by-sourcetype-in-6-6/m-p/359304#M65558</link>
    <description>&lt;P&gt;I just upgraded from 6.5.6 to 6.6.5, and some searches I was doing in my personal dashboard stopped working.&lt;/P&gt;

&lt;P&gt;Through 6.5 I've been using some RT searches to watch the top 10 sourcetypes getting indexed over the past hour. These searches are based on some I found in the old Deployment Monitor app, and start by searching "index=_internal source=license_usage.log type=Usage", then breaking down the results so as to create a stacked area chart. One dashboard panel was broken down by ST, the other by host. Using these I could contact one of my users and note that they were sending an unusual amount of events, in case they weren't aware of that.&lt;/P&gt;

&lt;P&gt;Now that I'm running 6.6, those searches don't return any results, as the license usage is being tracked in the license_usage_summary.log file, which is forwarded to the _telemetry index, as I learned looking at the searches in the Monitoring Console. I have looked through the MC, but so far haven't found any panels that I can borrow from. In the License Usage choices under Indexing, the only choices I have are either Previous 30 Days or Today. In Previous I can split by ST, but not in Today, so it won't meet my requirements for ST usage anomalies.&lt;/P&gt;

&lt;P&gt;Does anyone have  a suggestion for how to monitor the highest ST usage over the past hour or so?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:23:31 GMT</pubDate>
    <dc:creator>rkilen</dc:creator>
    <dc:date>2020-09-29T17:23:31Z</dc:date>
    <item>
      <title>License Usage by sourcetype in 6.6</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/License-Usage-by-sourcetype-in-6-6/m-p/359304#M65558</link>
      <description>&lt;P&gt;I just upgraded from 6.5.6 to 6.6.5, and some searches I was doing in my personal dashboard stopped working.&lt;/P&gt;

&lt;P&gt;Through 6.5 I've been using some RT searches to watch the top 10 sourcetypes getting indexed over the past hour. These searches are based on some I found in the old Deployment Monitor app, and start by searching "index=_internal source=license_usage.log type=Usage", then breaking down the results so as to create a stacked area chart. One dashboard panel was broken down by ST, the other by host. Using these I could contact one of my users and note that they were sending an unusual amount of events, in case they weren't aware of that.&lt;/P&gt;

&lt;P&gt;Now that I'm running 6.6, those searches don't return any results, as the license usage is being tracked in the license_usage_summary.log file, which is forwarded to the _telemetry index, as I learned looking at the searches in the Monitoring Console. I have looked through the MC, but so far haven't found any panels that I can borrow from. In the License Usage choices under Indexing, the only choices I have are either Previous 30 Days or Today. In Previous I can split by ST, but not in Today, so it won't meet my requirements for ST usage anomalies.&lt;/P&gt;

&lt;P&gt;Does anyone have  a suggestion for how to monitor the highest ST usage over the past hour or so?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:23:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/License-Usage-by-sourcetype-in-6-6/m-p/359304#M65558</guid>
      <dc:creator>rkilen</dc:creator>
      <dc:date>2020-09-29T17:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: License Usage by sourcetype in 6.6</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/License-Usage-by-sourcetype-in-6-6/m-p/359305#M65559</link>
      <description>&lt;P&gt;AFAIK, the licnese_usage.log are still being logged and does allow splitting by sourcetype. Can you try running your &lt;CODE&gt;index=_internal source=*license_usage.log&lt;/CODE&gt; on your license master instance?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/AboutSplunksLicenseUsageReportView#Previous_30_Days_tab" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/AboutSplunksLicenseUsageReportView#Previous_30_Days_tab&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:27:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/License-Usage-by-sourcetype-in-6-6/m-p/359305#M65559</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-09-29T17:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: License Usage by sourcetype in 6.6</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/License-Usage-by-sourcetype-in-6-6/m-p/359306#M65560</link>
      <description>&lt;P&gt;hey try this:&lt;/P&gt;

&lt;P&gt;Just run below search for any custom time select &lt;CODE&gt;today&lt;/CODE&gt; in timepicker.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal [`set_local_host`] source=*license_usage.log* type="Usage" | eval h=if(len(h)=0 OR isnull(h),"(SQUASHED)",h) | eval s=if(len(s)=0 OR isnull(s),"(SQUASHED)",s) | eval idx=if(len(idx)=0 OR isnull(idx),"(UNKNOWN)",idx) | bin _time span=1d | stats sum(b) as b by _time, pool, s, st, h, idx   | timechart span=1d sum(b) AS volumeB by st fixedrange=false  | join type=outer _time [search index=_internal [`set_local_host`] source=*license_usage.log* type="RolloverSummary" earliest=-30d@d | eval _time=_time - 43200 | bin _time span=1d | stats latest(stacksz) AS "stack size" by _time] | fields - _timediff  | foreach * [eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;=round('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'/1024/1024/1024, 3)]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Let me know if this helps you!&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2018 05:17:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/License-Usage-by-sourcetype-in-6-6/m-p/359306#M65560</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-02T05:17:22Z</dc:date>
    </item>
  </channel>
</rss>

