<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Daily License Usage Based on Source Information Along with Host, Index &amp;amp; Sourcetype Information in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/689954#M235048</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;There is a requirement&amp;nbsp; to get the license usage split in GB on daily basis for the top 20 log sources along with the host, index and sourcetype details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So kindly help with the query.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2024 10:08:53 GMT</pubDate>
    <dc:creator>anandhalagaras1</dc:creator>
    <dc:date>2024-06-07T10:08:53Z</dc:date>
    <item>
      <title>Daily License Usage Based on Source Information Along with Host, Index &amp; Sourcetype Information</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/689954#M235048</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;There is a requirement&amp;nbsp; to get the license usage split in GB on daily basis for the top 20 log sources along with the host, index and sourcetype details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So kindly help with the query.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 10:08:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/689954#M235048</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2024-06-07T10:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Daily License Usage Based on Source Information Along with Host, Index &amp; Sourcetype Information</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/689966#M235050</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if you see in the Monitoring Console App [Settings &amp;gt; Monitoring Console &amp;gt; Indexing &amp;gt; icense Usage &amp;gt; Historic License Usage] or in License Concuption Report [Settings &amp;gt; Licensing &amp;gt; Usage Report&amp;gt; Previous 60 days &amp;gt; Split by ...] youcan find the searches you need.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 11:55:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/689966#M235050</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-07T11:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Daily License Usage Based on Source Information Along with Host, Index &amp; Sourcetype Information</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/689974#M235053</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using Splunk Cloud version 9.1.2308.203. Following your instructions, I navigated to Cloud Monitoring Console --&amp;gt; License Usage and found the following options in the Cloud Monitoring Console App:&lt;BR /&gt;- Entitlement&lt;BR /&gt;- Ingest&lt;BR /&gt;- Workload&lt;BR /&gt;- Storage Summary&lt;BR /&gt;- Searchable Storage (DDAS)&lt;BR /&gt;- Archive Storage (DDAA)&lt;BR /&gt;- Federated Search for Amazon S3&lt;/P&gt;&lt;P&gt;Our Cloud Monitoring Console app is version 3.25.0. Please let me know how to pull the top 20 or top 50 sources with the index and sourcetype information.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 12:35:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/689974#M235053</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2024-06-07T12:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Daily License Usage Based on Source Information Along with Host, Index &amp; Sourcetype Information</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/689976#M235054</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you should take the searches in Workload and adapt them to your requirements.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 12:52:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/689976#M235054</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-07T12:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Daily License Usage Based on Source Information Along with Host, Index &amp; Sourcetype Information</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/690176#M235081</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;When i navigate to the Cloud Monitoring Console--&amp;gt;License Usage--&amp;gt;Workload.&lt;/P&gt;
&lt;P&gt;I can see Indexing Process--&amp;gt;Peak SVC usage per hour split by indexing source. So when i navigate to the query in another search window.&amp;nbsp; I can see the query as below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=summary source="splunk-ingestion" [`sim_get_local_stack` | eval host="*.".stack.".*splunk*" | fields host]
| dedup keepempty=t _time idx st
| stats sum(ingestion_gb) as ingestion_gb by _time idx
| eventstats sum(ingestion_gb) as total_gb by _time
| eval pct=ingestion_gb/total_gb
| bin _time span=1h
| join _time
[ search index=summary source="splunk-svc-consumer" svc_consumer="data services" svc_usage=*
| fillnull value="" svc_consumer process_type search_provenances search_type search_app search_label search_user unified_sid search_modes labels search_head_names usage_source
| eval unified_sid=if(unified_sid="",usage_source,unified_sid)
| stats max(svc_usage) as utilized_svc by _time svc_consumer search_type search_app search_label search_user search_head_names unified_sid process_type
| timechart span=1h sum(utilized_svc) as svc_usage
]
| eval svc_usage=svc_usage*pct
| timechart useother=false span=1h sum(svc_usage) by idx&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to generate three separate reports, each identifying the top 10 items based on license usage in GB over the last 30 days. Specifically, I want to pull the following information:&lt;/P&gt;
&lt;P&gt;1. The top 10 indexes (excluding internal indexes).&lt;BR /&gt;2. The top 10 sourcetypes (excluding internal index sourcetypes).&lt;BR /&gt;3. The top 10 sources.&lt;/P&gt;
&lt;P&gt;These reports need to be scheduled to run every month. Could you please provide the queries for these three requirements?&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;</description>
      <pubDate>Mon, 10 Jun 2024 10:29:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Daily-License-Usage-Based-on-Source-Information-Along-with-Host/m-p/690176#M235081</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2024-06-10T10:29:06Z</dc:date>
    </item>
  </channel>
</rss>

