All Apps and Add-ons

How to get a time chart of license usage based on source for the last 7 days

pdantuuri0411
Explorer

How to get a time chart of license usage based on source for the last 7 days.

I tried the monitoring console to get the intended results but, it doesn't seem to give out the results for all source types.

Regards.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the MC has a panel that is close to what you need, copy it to your own app and modify it to do what you want.
Consider starting with the "Daily License Usage" panel in the "License Usage - Previous 30 Days" dashboard.

---
If this reply helps you, Karma would be appreciated.
0 Karma

pdantuuri0411
Explorer

Thank you for the quick reply @richgalloway

I used the below query and got the intended results based on source. However, I have a followup question.

The query gives 10 results and the rest of the results go to "OTHER", What is the criteria on what sources are shown and what sources are included in OTHER.

dmc_licensing_base_usage(dw07apl43.cityofchicago.org,"") | dmc_licensing_usage_all(dw07apl43.cityofchicago.org, dmc_licensing_stack_size_srch, dw07apl43.cityofchicago.org, "s", "") | sort -_time

0 Karma

to4kawa
Ultra Champion

check your search query with command+shift+E OR ctrl+shift+E
and modify timechart with useother=f

0 Karma
Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...