Installation

Determination of license usage

Gayathirik
Path Finder

How to determine max license usage of various indexers in GB for past 30 days also how to convert the KB to GB?

Tags (1)
0 Karma

dbourg_splunk
Splunk Employee
Splunk Employee

@richgalloway has the best answer to this (DMC). The answer from @dbcase is correct if you want to see your total license usage, but it is not split by indexer. Is there something in particular you are trying to determine at the indexer level?

0 Karma

dbcase
Motivator

Here is the query I use

index=_internal source="*license_usage.log" type=RolloverSummary | timechart span=1d sum(b) AS DailyVolume | eval DailyVolume=round(DailyVolume/1024/1024/1024,2) | eval License="5"|rename DailyVolume as "Daily Usage"

Change the eval License="5" to whatever your license number is

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Distributed Management Console (DMC) will show license usage by index for the last 30 days. Click Settings->Distributed Management Console then click Indexing->License Usage->License Usage - Past 30 days. Select "By Indexer" from the Split By drop-down.
Convert KB to GB by dividing by 1024.

---
If this reply helps you, Karma would be appreciated.

Gayathirik
Path Finder

I need to check on the license utilization of different indexers which are in bytes and to convert it to GB for the past 30 days.

If you can provide me with the query then it would help!!!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I still say the DMC is the better approach, but this query may also help.

index=_internal source=*license* | stats sum(b) as Bytes by splunk_server | eval GB=Bytes/1024/1024/1024 | table splunk_server GB
---
If this reply helps you, Karma would be appreciated.
0 Karma

dbourg_splunk
Splunk Employee
Splunk Employee

Also be aware that there are different types of events in the license_usage.log. RolloverSummary is the one you want to use to determine overall volume.

0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...