We have allocated 500GB of data per day to index in our environment but everyday the utilization is getting crossed more than 500GB and we have deployed Splunk 6.5 version installed in our environment so generally i can able to pull the report only for last 30 days in our License Usage report which has been configured based on Index, Sourcetype & Host information.
But now we want to analyse the trend for last 1 year based on Sourcetype, Index and Host information so that if there is a real need then we will purchase additional license so can you able to help with a search query with the below mentioned key points:
--> We need to pull the license utilization report for last 1 year something like that out of 500 GB how much license is getting utilized every day.
-->Also we want to segregate the license utilization based on Host, Source and Sourcetype.
So it would be really helpful if you can able to provide me the search query or a way to extract the report.