All Apps and Add-ons

How can I find out which systems are generating the most output

marvatwork
Explorer

About a week ago, daily usage jumped SIGNIFICANTLY. I was no where near the license capacity, now i'm exceeding it and I'm not sure what is generating it.
What can I do to find out what is generating most of the output.

0 Karma

Jeff_Lightly_Sp
Communicator

Got to Settings-System-Licensing. Click on Usage Report button,select Previous 30 days tab and from the Split by tab Split by Host from the dropdown. This may show the offending host if its not lumped in with "Other".

martin_mueller
SplunkTrust
SplunkTrust

There's also the SoS app to look at for current indexing throughput, or the new-in-6.2 distributed management console that has the same info in a prettier wrapping. License Usage Report will be easiest though because it's built-in.

0 Karma

Jeff_Lightly_Sp
Communicator

Martin Mueller also recently posted a nice solution that may help you too. See:

http://answers.splunk.com/answers/183473/how-to-find-the-daily-average-of-indexed-data-by-h.html

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...