<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can we get usage related data from index ? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705481#M14221</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274468"&gt;@arjun&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what's your requirement: to know the volume for each customer? or what else?&lt;/P&gt;&lt;P&gt;Could you better describe your environment and your situation?&lt;/P&gt;&lt;P&gt;E.g.: have you a multi-tenant environment or not?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 28 Nov 2024 14:04:58 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-11-28T14:04:58Z</dc:date>
    <item>
      <title>How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705480#M14220</link>
      <description>&lt;P&gt;How can we locate usage related data from splunk, I have onpremise splunk instance and looking for usage and billing related data grouped by day.&lt;BR /&gt;I am not able to locate data in any index.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 13:58:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705480#M14220</guid>
      <dc:creator>arjun</dc:creator>
      <dc:date>2024-11-28T13:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705481#M14221</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274468"&gt;@arjun&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what's your requirement: to know the volume for each customer? or what else?&lt;/P&gt;&lt;P&gt;Could you better describe your environment and your situation?&lt;/P&gt;&lt;P&gt;E.g.: have you a multi-tenant environment or not?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 14:04:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705481#M14221</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-11-28T14:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705482#M14222</link>
      <description>&lt;P&gt;HI&amp;nbsp;@&lt;A class="" href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352" target="_self"&gt;&lt;SPAN class=""&gt;gcusello&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In splunk we monitor devices or Host and we get logs from them what i need to know how much memory (in GB) has been utilised by those host or log source where does splunk store such data in case of Onpremise instance ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 14:14:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705482#M14222</guid>
      <dc:creator>arjun</dc:creator>
      <dc:date>2024-11-28T14:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705484#M14223</link>
      <description>&lt;P&gt;Start with the DMC (Distributed Monitoring Console) to review the License usage broken down by index.&amp;nbsp; This will share with you the daily ingest records for the last 30 days broken down by index.&amp;nbsp; This is only a starting point as depending on how your environment was setup you may have very specific indexes or things may have been aggregated into only a few indexes.&lt;/P&gt;&lt;P&gt;From there you can start decided what questions come next.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 14:23:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705484#M14223</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-11-28T14:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705494#M14227</link>
      <description>&lt;P&gt;Do you mean you want to monitor your Splunk infrastructure usage or do you ingest some data regarding "external" hosts? For the former as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194981"&gt;@dural_yyz&lt;/a&gt; mentioned, check Monitoring Console. You can also gather metrics from the _metrics index. For the latter - it depends on your environment. Splunk "just" happily gets the data you throw at it and can manipulate and search it. But it's up to your architects and admins to tell you where they set up the data and what it's made of.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 15:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705494#M14227</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-28T15:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705540#M14231</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274468"&gt;@arjun&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;to monitor windows or Linux machines having a Universal Forwarder installed, you have to install on these UFs the related add on (Linux &lt;A href="https://splunkbase.splunk.com/app/833" target="_blank"&gt;https://splunkbase.splunk.com/app/833&lt;/A&gt; or windows&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/742" target="_blank"&gt;https://splunkbase.splunk.com/app/742&lt;/A&gt;&amp;nbsp;) enabling the input stanza for memory monitoring.&lt;/P&gt;&lt;P&gt;In this way you'll have the logs to use in your searches.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 06:48:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705540#M14231</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-11-29T06:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705787#M14232</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;, We have many client who uses splunk and we need to get some data from those splunk server&lt;/P&gt;&lt;P&gt;I am trying to get a way with SPL to get those data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basic Data that we need from those splunk system are&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1 )&amp;nbsp; detailed information about resources, their usage, and associated costs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But i am not sure which index will have this data ? does _telemetry index will have all required data to know how much utilisation has been done day by day ?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hope this define my requirement clearly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 09:06:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705787#M14232</guid>
      <dc:creator>arjun</dc:creator>
      <dc:date>2024-12-03T09:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705789#M14233</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274468"&gt;@arjun&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;multi tenency&amp;nbsp; implementation isn't a Community job and it requires an analysis and a design by a Splunk Architect.&lt;/P&gt;&lt;P&gt;You should define rules to identify customers and assign to each of them an index overriding the default.&lt;/P&gt;&lt;P&gt;So first job is to identify rules (regexes) and then apply on your Heavy Forwarders (if present) or on your Indexers something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# transforms.conf 
[overrideindex_customer1]
DEST_KEY =_MetaData:Index
REGEX = .
FORMAT = customer1_index

# props.conf 
[host::customer1_host]
TRANSFORMS-index = overrideindex_customer1&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 09:42:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705789#M14233</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-03T09:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705793#M14234</link>
      <description>&lt;P&gt;Your description is still way incomplete. But whatever your exact use case is, I agree with &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; that it's something that you should work with your local Splunk Partner on - have an experienced Architect or Consultant go through your use case and see what can be done and how.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 10:19:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/705793#M14234</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-03T10:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/706110#M14235</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; i am trying to get data related to usage and billing from splunk, here is query i am using for that&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=_telemetry source=*license_usage_summary.log*
| bin _time span=1d
| stats sum(b) as TotalBytes by _time
| eval GB=round(TotalBytes / (1024 * 1024 * 1024), 2)
| timechart span=1d values(GB) as "Daily Indexed GB"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And per my research spulnk has few more such index like _internal and _audit&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I just want to know if this is correct approach or not&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 15:07:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/706110#M14235</guid>
      <dc:creator>arjun</dc:creator>
      <dc:date>2024-12-06T15:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: How can we get usage related data from index ?</title>
      <link>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/706113#M14236</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274468"&gt;@arjun&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you can calculate the License consuption per day using the [Settings &amp;gt; License &amp;gt; License Consuption &amp;gt; Past days &amp;gt; by index ].&lt;/P&gt;&lt;P&gt;using your search you have all the license consuption, you cannot divide them for customer, as I already said: multitenency isn't a Community topic, it requires a Splunk PS or a Certified Architect that already did this job (like me).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 08:59:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-we-get-usage-related-data-from-index/m-p/706113#M14236</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-06T08:59:05Z</dc:date>
    </item>
  </channel>
</rss>

