Dashboards & Visualizations

After upgrading from Splunk 6.1 to 6.3, why does our license usage report show incorrect results?


We are using this search for a Splunk license usage dashboard. it works fine in Splunk 6.1, but when we run this from a 6.3 search head, it gives twice the values.

We switched off the load balancer pointing to the the old search head now have invalid data.

index=_internal source=*license_usage.log* type=Usage | timechart span=1d sum(b) as bytes | eval GB = round(bytes/1024/1024/1024,5) | fields _time GB


0 Karma


Do you have a license master in your environment? Does Splunk's Licensing dashboard display correct results? Have you looked at the raw events from your search to see if there are unexpected hosts/sources/etc included in the data that might explain the skewed numbers?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...