Getting Data In

REST Calls for license usage

mphalak
New Member

Today I have this search to alert me on license usage going beyond certain threshold:
Search: index=_internal source=*license_usage.log pool="auto_generated_pool_enterprise"| eval GB=b/1024/1024/1024 | stats sum(GB) as current_license_usage_auto_generated_pool_GB by pool

Due to some reasons I am getting wrong results for the above ....How can I change this search to use rest endpoints ??

Tags (2)
0 Karma

yannK
Splunk Employee
Splunk Employee

on 4.3, please specify a type of records, otherwise you may count things twice.

type=Usage

type=RolloverSummary

see the difference here : http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

0 Karma

mphalak
New Member

Thanks I was able to get teh resulst with this search:

| rest /services/licenser/pools | where title= "auto_generated_pool_enterprise" | table used_bytes, title | eval GB=used_bytes/1024/1024/1024

BUT now when I set the same as saved search and try to send alert when GB>1 I see the following error:

DEBUG: search context: user="admin", app="tto_search", bs-pathname="/opt/splunk/etc"
INFO: No matching fields exist
WARN: Unable to fetch REST endpoint '/services/licenser/pools' from ''

ANY IDEA ???

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...