My boss is asking that we start getting more detailed tracking of our Splunk instance as a way of better justifying our various expenses. Effectively adoption and cost monitoring.
Any apps worth checking out that might be able to start with? Any queries or ideas you personally use?
So far I am thinking a summary index with the following
1) users per day
2) searches per day
3) query response time per day
4) License usage by host type per day
5) host count per day
6) New jiras per day
7) alerts sent out per day