All Apps and Add-ons

License manager not reporting past 30 days (6.6.4)

halbeisendv
Path Finder

The License Manager server does not report past 30 days. The DMC, on a different server, reports satisfactorily and when I grab the SPL from the LM and run it on the Search Head Cluster the results are as expected. We have already ensured followed the guidance in https://docs.splunk.com/Documentation/Splunk/6.6.4/Admin/LicenseUsageReportViewexamples. Help/guidance is appreciated.

alt text

And, we verified are settings with the boundaries of these recommendations
alt text

0 Karma

Vijeta
Influencer

@halbeisendv Have you tried below query, you can run it on search head.

index=_internal source=*license_usage.log type=Usage host=<your license master>
0 Karma

jkat54
SplunkTrust
SplunkTrust

Does the license master have any search peers? Pretend its trying to be a search head and follow this guidance:

https://docs.splunk.com/Documentation/Splunk/7.3.0/DistSearch/Configuredistributedsearch

halbeisendv
Path Finder

Thank you for your response, but that was not the resolution to the problem we are experiencing.

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

The links copied in are more related to the fact that _internal and thus license_usage.log is only retained for 30 days and then it's buckets freeze by default. So that would be why you can't retrieve license info for days <30 days out. Can you run any searches from the license master?

0 Karma

halbeisendv
Path Finder

This problem is that the License Manager Server will not display license utilization for the past 30 days. Yes, I can run searches from the License Manager. Thank you for your response and assistance.

0 Karma
Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...