<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Query for license utilization in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-for-license-utilization/m-p/760298#M243433</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need a splunk query to find the license utilization per host per day in last 4 months, to know which host/server is most noisy and utilizing most consumption in splunk.&lt;/P&gt;</description>
    <pubDate>Sat, 18 Apr 2026 07:40:12 GMT</pubDate>
    <dc:creator>kjain041523</dc:creator>
    <dc:date>2026-04-18T07:40:12Z</dc:date>
    <item>
      <title>Splunk Query for license utilization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-for-license-utilization/m-p/760298#M243433</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need a splunk query to find the license utilization per host per day in last 4 months, to know which host/server is most noisy and utilizing most consumption in splunk.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Apr 2026 07:40:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-for-license-utilization/m-p/760298#M243433</guid>
      <dc:creator>kjain041523</dc:creator>
      <dc:date>2026-04-18T07:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for license utilization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-for-license-utilization/m-p/760299#M243434</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/316545"&gt;@kjain041523&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the search you're searching is available in [Settings &amp;gt; Licensing &amp;gt; Usage Report &amp;gt;&amp;nbsp; Previous 6 days &amp;gt; Split by host] or in the Monitoring Console at [Indexing &amp;gt; License usage &amp;gt; Historic License usage &amp;gt; Split by host ].&lt;/P&gt;&lt;P&gt;This report is for 30 days but you can easily modify it for 120 days:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal 
    [ rest splunk_server=local /services/server/info 
    | return host] source=*license_usage.log* type="Usage" 
| eval h=if(len(h)=0 OR isnull(h),"(SQUASHED)",h) 
| eval s=if(len(s)=0 OR isnull(s),"(SQUASHED)",s) 
| eval idx=if(len(idx)=0 OR isnull(idx),"(UNKNOWN)",idx) 
| bin _time span=1d 
| stats sum(b) as b by _time, pool, s, st, h, idx 
| timechart span=1d sum(b) AS volumeB by h fixedrange=false 
| join type=outer _time 
    [ search index=_internal 
        [ rest splunk_server=local /services/server/info 
        | return host] source=*license_usage.log* type="RolloverSummary" earliest=-120d@d 
    | eval _time=_time - 43200 
    | bin _time span=1d 
    | dedup _time stack 
    | stats sum(stacksz) AS "stack size" by _time] 
| fields - _timediff 
| foreach "*" 
    [ eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;=round('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'/1024/1024/1024, 3)]&lt;/LI-CODE&gt;&lt;P&gt;The problem could be another: are you sure that the retention of your _internal index is more than 4 months?&lt;/P&gt;&lt;P&gt;Usually it's less, so you could not have the logs dor this search!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 18 Apr 2026 08:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-for-license-utilization/m-p/760299#M243434</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-04-18T08:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for license utilization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-for-license-utilization/m-p/760310#M243438</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/316545"&gt;@kjain041523&lt;/a&gt;&amp;nbsp;As mentioned, the easiest way to use the Monitoring Console's built in License Usage report under Settings &amp;gt; Licensing.&amp;nbsp;&lt;SPAN&gt;Keep in mind that only the License Manager and Monitoring Console have access to the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;license_usage.log&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;information from where we are pulling the usage information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can query _internal index alternatively from your License Manager. Use the below references to understand license_usage.log to build your custom query if required.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please note that the &lt;STRONG&gt;_internal&lt;/STRONG&gt; index usually has shorter retention (often &lt;STRONG&gt;30 days&lt;/STRONG&gt; by default), so you may not have four months of data unless retention has been increased in your indexes.conf file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ref:&amp;nbsp;&lt;A href="https://splunk.my.site.com/customer/s/article/Create-a-report-based-on-licence-usage-log" target="_blank" rel="noopener"&gt;Create a report based on licence_usage.log | Splunk&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/troubleshoot/9.4/splunk-enterprise-log-files/what-splunk-software-logs-about-itself" target="_blank" rel="noopener"&gt;What Splunk software logs about itself | Splunk Enterprise (last updated 2025-07-04T12:39:10.038Z)&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this post addressed your question, you can:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Give it&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;karma&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to show appreciation&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Mark it as the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;solution&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;if it solved your issue&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":heavy_check_mark:"&gt;✔️&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Add a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;comment&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;if you’d like more details&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":pencil:"&gt;✏️&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Apr 2026 18:16:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-for-license-utilization/m-p/760310#M243438</guid>
      <dc:creator>kknairr</dc:creator>
      <dc:date>2026-04-19T18:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for license utilization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-for-license-utilization/m-p/760351#M243440</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/316545"&gt;@kjain041523&lt;/a&gt;&amp;nbsp;may i know if the issue is resolved or do you have further queries?&lt;/P&gt;&lt;P&gt;if its resolved, could you pls accept it as solution, thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------&lt;BR /&gt;If this post or any post addressed your question, could you pls:&lt;BR /&gt;Give it karma to show appreciation&lt;/P&gt;&lt;P&gt;PS - As of Apr 2026, my Karma Given is 2290 and my Karma Received is 494, lets revamp the Karma Culture!&lt;BR /&gt;Thanks and best regards, Sekar&lt;BR /&gt;----------------------------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 12:33:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-for-license-utilization/m-p/760351#M243440</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2026-04-21T12:33:28Z</dc:date>
    </item>
  </channel>
</rss>

