Monitoring Splunk

How to find out how many license violations have occurred in the last 30 days in Splunk 6.2?

niklucky02
Explorer

I have installed Splunk 6.2 version and it shows a license violation under category 'license_window'. Is there any way we can find out how many violations have occurred in last 30 days in version 6.2?

0 Karma
1 Solution

phadnett_splunk
Splunk Employee
Splunk Employee

The best way to do this is to monitor the 30 day License Usage Report View (LURV) in Settings > LIcensing > Usage Report > Previous 30 Days

View solution in original post

phadnett_splunk
Splunk Employee
Splunk Employee

The best way to do this is to monitor the 30 day License Usage Report View (LURV) in Settings > LIcensing > Usage Report > Previous 30 Days

phadnett_splunk
Splunk Employee
Splunk Employee

@niklucky02 You could use a search like this to see each time a warning occurs for the pool. You have 5 or more warnings in a rolling 30-day period before a violation for the pool occurs.

index=_internal sourcetype=splunkd component=LMStackMgr "A warning has been recorded for all members"

niklucky02
Explorer

Thanks Phadnett! The query worked but it was showing 5 violations whereas my search didn;t lock out. Anyways, I will keep this query as the message is exactly what I was looking for.

niklucky02
Explorer

@phadnett: I see some variations in the number of violations messages that I see under LURV and the reason I posed this question. My question is there a pattern inside splunk logs on the license master server that would help me to see that I have violated 3 times in last 30 days or an alternate splunk query?

0 Karma

niklucky02
Explorer

Violation alerts under licensing tab are not consistent and it seems to retrieve those messages using REST API. Re-framing my earlier question, is there a way to track the number of violations from the splunk logs?

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...