<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Host License Usage in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751619#M10996</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308817"&gt;@DataWrangler&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I have assisted customers set up the Splunk App for Chargeback and they've mentioned that they were able to distribute the costs as per their requirement within the different business units/orgs. You need to make sure that you enter the right proportion in the lookup while configuring the business units. I do agree that a one time setup is a complicated process, but it does eventually help with the task.&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Tejas.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Aug 2025 07:39:34 GMT</pubDate>
    <dc:creator>tej57</dc:creator>
    <dc:date>2025-08-14T07:39:34Z</dc:date>
    <item>
      <title>Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751506#M10988</link>
      <description>&lt;P&gt;When running license usage reports by host we are hitting the squash_threshold in server.conf.&lt;/P&gt;&lt;P&gt;I've researched this and the only solution I can see it to increase the&amp;nbsp;&lt;SPAN&gt;squash_threshold beyond the number of combinations of index, host, source and sourcetype, which I calculate by running this search:&lt;BR /&gt;&lt;BR /&gt;| tstats count AS tuples where index IN (uk*, us*) by index host source sourcetype&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The docs say there will be an impact on memory, though there's no indication on what that might look like.&lt;/P&gt;&lt;P&gt;Do you have any real world experience of the impact of doing this?&lt;/P&gt;&lt;P&gt;Is the license usage log the only method of calculating host based usage? It is from what I've found so far in my reading.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 07:44:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751506#M10988</guid>
      <dc:creator>DataWrangler</dc:creator>
      <dc:date>2025-08-13T07:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751546#M10989</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308817"&gt;@DataWrangler&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I do agree to the document to not increase the squash_threshold. However, if you want host based utilization, you can check metrics.log with group=per_host_thruput and then sum up the values of kb and group it by series. The series field will contain the host values for group=per_host_thruput.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal source=*var/log/splunk/metrics.log* group=per_host_thruput
| eval gb = round(kb/1024/1024,2)
| timechart sum(gb) as total_ingestion by series&lt;/LI-CODE&gt;&lt;P&gt;I haven't tried experimenting the value of squash_threshold.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Tejas.&lt;/P&gt;&lt;P&gt;---&lt;BR /&gt;If the above solution helps, an upvote is appreciated..!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 13:44:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751546#M10989</guid>
      <dc:creator>tej57</dc:creator>
      <dc:date>2025-08-13T13:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751555#M10990</link>
      <description>As metrics reports only metrics on top X, this didn't get real amount as there probably are many periods when another nodes have more traffic.</description>
      <pubDate>Wed, 13 Aug 2025 14:10:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751555#M10990</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-08-13T14:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751557#M10991</link>
      <description>&lt;P&gt;What is the real work issue which you are trying to solve? And is this one shot or continuously needed answer to it?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 14:12:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751557#M10991</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-08-13T14:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751566#M10992</link>
      <description>&lt;P&gt;We run Splunk in a project and the costs are billed to each part of the project as they are funded separately through separate changes.&lt;/P&gt;&lt;P&gt;So when a new set of servers are built, I'd like to be able to report with reasonable accuracy that these 10 new web servers are using say 5GB of license on average per day for billing.&lt;/P&gt;&lt;P&gt;This will also help us predict future usage when we add another 5 servers of the same type.&lt;/P&gt;&lt;P&gt;It will be an ongoing requirement to accurately report costs and bill correctly.&lt;/P&gt;&lt;P&gt;I've started investigating the Splunk App for Chargeback which seems useful but overly complex for this requirement.&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/5688" target="_blank"&gt;https://splunkbase.splunk.com/app/5688&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 14:40:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751566#M10992</guid>
      <dc:creator>DataWrangler</dc:creator>
      <dc:date>2025-08-13T14:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751573#M10993</link>
      <description>&lt;P&gt;You can either create an indexed field holding the raw event length so you can quickly do tstats.&lt;/P&gt;&lt;P&gt;Or - even better - create a simple datamodel holding length of your events as a calculated field. And accelerate it.&lt;/P&gt;&lt;P&gt;It will have _some_ impact on your environment but still better than plowing through raw data every time you need a report on your license usage.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 15:23:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751573#M10993</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-08-13T15:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751576#M10994</link>
      <description>&lt;P&gt;You can also go for configuring the Chargeback App for Splunk. It was created for the same intended purpose. The configuration is quite complex at the initial stage, but once you setup the lookup files it needs, you'll get a clear view of how much of the fund is consumed by which part of the project/team/business etc.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 15:27:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751576#M10994</guid>
      <dc:creator>tej57</dc:creator>
      <dc:date>2025-08-13T15:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751618#M10995</link>
      <description>&lt;P&gt;If you or anyone else has experience of using the chargeback app please do share it. I'm sure others will find it helpful too.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2025 07:32:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751618#M10995</guid>
      <dc:creator>DataWrangler</dc:creator>
      <dc:date>2025-08-14T07:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751619#M10996</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308817"&gt;@DataWrangler&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I have assisted customers set up the Splunk App for Chargeback and they've mentioned that they were able to distribute the costs as per their requirement within the different business units/orgs. You need to make sure that you enter the right proportion in the lookup while configuring the business units. I do agree that a one time setup is a complicated process, but it does eventually help with the task.&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Tejas.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2025 07:39:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751619#M10996</guid>
      <dc:creator>tej57</dc:creator>
      <dc:date>2025-08-14T07:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751620#M10997</link>
      <description>&lt;P&gt;Two good options there. So I can see we have as is often the case with Splunk, different ways to tackle this issue.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Increase the squash_threshold in server.conf to something larger than our tuple count - has an unquantified memory impact.&lt;/LI&gt;&lt;LI&gt;Eval a field from _raw event length with len() - due to characters not always being 1 byte won't be 100% accurate but close enough to track usage.&lt;/LI&gt;&lt;LI&gt;Create a datamodel to store the field from option 2 using a calculated field.&lt;/LI&gt;&lt;LI&gt;Invest time to figure out the&amp;nbsp;&lt;SPAN&gt;Splunk App for Chargeback.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;I will go with the quick option 2 and constrain this to the indexes / hosts I need to report on. I can work through the others when I get some quiet time&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks everyone for your responses which helped me think this through and find a practical solution.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2025 07:44:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751620#M10997</guid>
      <dc:creator>DataWrangler</dc:creator>
      <dc:date>2025-08-14T07:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751625#M10998</link>
      <description>&lt;P&gt;The third option is actually kinda like "option 2 on steroids". For a one-off thing, a simple search over raw data will probably suffice. If you're planning on doing this often and especially if your data set is big, you will want to accelerate that somehow.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2025 08:44:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751625#M10998</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-08-14T08:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Host License Usage</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751632#M10999</link>
      <description>&lt;P&gt;You are right. For now this will be an infrequent ask perhaps monthly or quarterly, so I will run it adhoc or schedule it to run as a report overnight.&lt;/P&gt;&lt;P&gt;Definitely worth looking at making this more efficient.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2025 10:02:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Host-License-Usage/m-p/751632#M10999</guid>
      <dc:creator>DataWrangler</dc:creator>
      <dc:date>2025-08-14T10:02:23Z</dc:date>
    </item>
  </channel>
</rss>

