Searching: When a host reaches 1gb memory consumed per day fire an alert?
This will has to be real-time.
there a little confusion:
if you're speaking of licensing, violation is countered once a day at midnight.
if you're speaking of memory usage it's another thing.
If instead you want to have an alert when the license consuption of an host reaches 1 GB (not memory!), you can use one of the searches that you can find in [Settings -- Licensing -- Usage Report]:
index=_internal [`set_local_host`] source=*license_usage.log* type="Usage" earliest=-d@d latest=now
| stats sum(b) as b by h
| eval b=round(b/1024/1024/1024,2)
| where b>1
It isn't a good idea to use a real time alert because it uses too much resources, you could run this alert with a frequency to define (5 minutes, 1 hour, etc...).