<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After upgrading from Splunk 6.1 to 6.3, why does our license usage report show incorrect results? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/After-upgrading-from-Splunk-6-1-to-6-3-why-does-our-license/m-p/234118#M14483</link>
    <description>&lt;P&gt;Do you have a license master in your environment?  Does Splunk's Licensing dashboard display correct results?  Have you looked at the raw events from your search to see if there are unexpected hosts/sources/etc included in the data that might explain the skewed numbers? &lt;/P&gt;</description>
    <pubDate>Sat, 05 Mar 2016 14:09:21 GMT</pubDate>
    <dc:creator>maciep</dc:creator>
    <dc:date>2016-03-05T14:09:21Z</dc:date>
    <item>
      <title>After upgrading from Splunk 6.1 to 6.3, why does our license usage report show incorrect results?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/After-upgrading-from-Splunk-6-1-to-6-3-why-does-our-license/m-p/234117#M14482</link>
      <description>&lt;P&gt;We are using this search for a Splunk license usage dashboard. it works fine in Splunk 6.1, but when we run this from a 6.3 search head, it gives twice the values.&lt;/P&gt;

&lt;P&gt;We switched off the load balancer pointing to the the old search head now have invalid data.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*license_usage.log* type=Usage | timechart span=1d sum(b) as bytes | eval GB = round(bytes/1024/1024/1024,5) | fields _time GB
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Anil.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Mar 2016 01:59:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/After-upgrading-from-Splunk-6-1-to-6-3-why-does-our-license/m-p/234117#M14482</guid>
      <dc:creator>athorat</dc:creator>
      <dc:date>2016-03-05T01:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading from Splunk 6.1 to 6.3, why does our license usage report show incorrect results?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/After-upgrading-from-Splunk-6-1-to-6-3-why-does-our-license/m-p/234118#M14483</link>
      <description>&lt;P&gt;Do you have a license master in your environment?  Does Splunk's Licensing dashboard display correct results?  Have you looked at the raw events from your search to see if there are unexpected hosts/sources/etc included in the data that might explain the skewed numbers? &lt;/P&gt;</description>
      <pubDate>Sat, 05 Mar 2016 14:09:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/After-upgrading-from-Splunk-6-1-to-6-3-why-does-our-license/m-p/234118#M14483</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2016-03-05T14:09:21Z</dc:date>
    </item>
  </channel>
</rss>

