Getting Data In

REST Calls for license usage

mphalak
New Member

Today I have this search to alert me on license usage going beyond certain threshold:
Search: index=_internal source=*license_usage.log pool="auto_generated_pool_enterprise"| eval GB=b/1024/1024/1024 | stats sum(GB) as current_license_usage_auto_generated_pool_GB by pool

Due to some reasons I am getting wrong results for the above ....How can I change this search to use rest endpoints ??

Tags (2)
0 Karma

yannK
Splunk Employee
Splunk Employee

on 4.3, please specify a type of records, otherwise you may count things twice.

type=Usage

type=RolloverSummary

see the difference here : http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

0 Karma

mphalak
New Member

Thanks I was able to get teh resulst with this search:

| rest /services/licenser/pools | where title= "auto_generated_pool_enterprise" | table used_bytes, title | eval GB=used_bytes/1024/1024/1024

BUT now when I set the same as saved search and try to send alert when GB>1 I see the following error:

DEBUG: search context: user="admin", app="tto_search", bs-pathname="/opt/splunk/etc"
INFO: No matching fields exist
WARN: Unable to fetch REST endpoint '/services/licenser/pools' from ''

ANY IDEA ???

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...