All Apps and Add-ons
Highlighted

I have 40GB of license usage each day for st=config_file, so why are there no events for sourcetype=config_file ?

Motivator

SplunkTAnix is ingesting config_file and our license is being used for it , so I should be able to find those events somewhere, but I cannot. Can anyone explain the results in this image?

alt text

Highlighted

Re: I have 40GB of license usage each day for st=config_file, so why are there no events for sourcetype=config_file ?

SplunkTrust
SplunkTrust

The license usage record shows timestamp of 10:31 AM and you're searching for different time range. I would suggest to run your search (also instead of index=* use index=os) for the timerange which include the time shown in license_usage.log.

0 Karma
Highlighted

Re: I have 40GB of license usage each day for st=config_file, so why are there no events for sourcetype=config_file ?

Motivator

LOL, not the best screenshot was it? I loaded a more consistent one.

This has been going on for weeks and there is never anything put in os.

0 Karma
Highlighted

Re: I have 40GB of license usage each day for st=config_file, so why are there no events for sourcetype=config_file ?

SplunkTrust
SplunkTrust

Now, could you verify if you've access to index=os, just to be sure? (check in Role/user setting or run the rest command | rest /services/authentication/users/<<yourUserName>> )

0 Karma
Highlighted

Re: I have 40GB of license usage each day for st=config_file, so why are there no events for sourcetype=config_file ?

Motivator

I do have access.

0 Karma
Highlighted

Re: I have 40GB of license usage each day for st=config_file, so why are there no events for sourcetype=config_file ?

SplunkTrust
SplunkTrust

Strange. So I'm guessing you've tried to run your search with a very wide time range as the data could be historical? Also, are you running this search from appropriate SH which has all the indexers as peers? can you see data for other sourcetypes in index=os?
Also, in your license usage search, the highlighted event has h="", do you get other records with a non-empty h value?

0 Karma
Highlighted

Re: I have 40GB of license usage each day for st=config_file, so why are there no events for sourcetype=config_file ?

Motivator

Searching for all time returns nothing for config_file, but I can see other sourcetypes.

Yes, there are valid h values for about 96% of the results in that search.

0 Karma
Highlighted

Re: I have 40GB of license usage each day for st=config_file, so why are there no events for sourcetype=config_file ?

Legend

Hi lycollicott,
you should use the license usage report [Settings -- License -- License Usage -- Last 30 days] divided by sourcetype to verify what you indexed in your sourcetypes.
Bye.
Giuseppe

0 Karma
Highlighted

Re: I have 40GB of license usage each day for st=config_file, so why are there no events for sourcetype=config_file ?

Motivator

That is how I already identified the problem.

0 Karma
Highlighted

Re: I have 40GB of license usage each day for st=config_file, so why are there no events for sourcetype=config_file ?

Legend

configfile is a sourcetype that you can find in your license usage report?
because in Splunk
TA_nix there isn't this sourcetype so I don't know where you call it.
Bye.
Giuseppe

0 Karma