Getting Data In

How to find metrics on license usage for my Cisco sourcetype?

hartfoml
Motivator

I want to find the license usage for my Cisco sourcetype. I found this on splunk answers

http://answers.splunk.com/answers/2180/license-usage-by-sourcetype

Thanks much for the help @Lowell

Unfortunately when I use this search: ...index=_internal sourcetype=splunkd source=*metrics* "group=per_sourcetype_thruput" series="cisco_syslog"...
I see very few events, 12 for the last 30 days??? If I add | stats sum(kb) I get 241 Kb for 30 days or ~8 Kb per day. Somehow this dose not sound right???

When I do ...sourcetype="cisco_syslog" | stats count... I get 201,686 event for just 7 days.

How can I make sure Splunk is capturing the right metrics for this sourcetype???

1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Give this a shot:

index=_internal source=*license_usage.log st="cisco_syslog"

Back when the linked question was answered that log didn't even exist yet...

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Give this a shot:

index=_internal source=*license_usage.log st="cisco_syslog"

Back when the linked question was answered that log didn't even exist yet...

hartfoml
Motivator

Thanks Martin

That did the trick

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...