I am trying to fine tune our license consumption and I can easily check the total number of events that match certain criteria (e.g: certain windows event ID for example). but how could I check the license consume by them? in other words, the total size of the data set of a query.
doing this, I could decide to blacklist certain events knowing beforehand that this blacklist will save X amount of MB a day of license.
unfortunately I cannot consult the license consumption as my splunk instance is dependent of a master instance managed by another institution. that is why I was wondering if I could make my own calculation , even though it is not 100% accurate.
maybe using something like
index=wineventlog EventCode=4689 | eval raw_length=len(_raw)
| stats sum(raw_length) as totalSize