- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to create a search and dashboard to display the daily license volume usage per index?
Hi splunkers,
Good day! I just to ask if possible to see the per index volume usage? Let's just say I have multiple indexes like index1 index2 index3. Then I want to create a dashboard that will check index1 index2 and index3 daily volume usage? Is it possible?
Thanks,
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

You can check-out an app I wrote for this too, it's free: https://splunkbase.splunk.com/app/2678/
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
what a great looking app. Like allot of other apps and queries you find on here try it or install it, doesn't work. Install it, no issue, load up the dashboard wow looks great. Let's use it.. go to license usage.. says populating, drum roll.. nothing no data.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Are you using Splunk Enterprise 6.x? Use the License Usage Reporting View. Settings > Licensing > Usage Report. See About the Splunk Enterprise license usage report view in the Admin Manual for more information.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi
it yes possible
index=* OR index=_*| stats count(Volume) by index
you will need to replace Volume by the field name which represente your volume in the index
for other information concerning this please let me know.
thanks and regards
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By the way Im doing this in a cluster mode. RF=3 SF=3
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why do these queries only show your top 10 indexes? I must be missing something obvious, It shows 10 indexes usually in a column.. but where are all the rest?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, thanks for the reply. Sorry Im just new to splunk, what is that particular field?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sorry sympatiko move Volume and run just
index=* OR index=_*| stats count by index
it give you eventypes volume by index but if you want data volume( like MB, GB) i think that its not possible.
you can just see volume data in this path: -> Settings -> Indexes
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
it give you eventypes volume by index but if you want data volume( like MB, GB) i think that its not possible
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for your help. I'll give it a shot. Thanks so much, long live!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

If you are admin user, login into Splunk console -> Settings -> Indexes. It will give you index name, size, event count etc.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, Im doing this in a cluster. Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi sympatiko,
Try with this query, index=* OR index=_* |timechart span=1d count by index
and you are going to see daily count by index.
Your query will be like: index=index1 OR index=index2 OR index= index3 |timechart span=1d count(volume) by index
where volume is your field .
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, thanks for the reply. Sorry Im just new to splunk, what is that particular field?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Wich particular field?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks casandra =). I'll try that one
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please if you don't satisfy let me now. If you satisfy, don't forget to vote.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try only with index=index1 OR index=index2 OR index= index3 |timechart span=1d count by index
