Hi,
I have made one search for finding the license usages for indexes that is given below.
index=_internal source=*license_usage.log type=usage (idx=*) | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals
Now the issue is if I pass through any index name to idx parameter, then it is giving result for the particular index, but when I am using *
for enlisting all indexes, then it is giving "no result found".
Please give suggestions and help me to sort out this issue.
Thanks in advance...
Able to see result for both
index=_internal source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals
And
index=_internal source="*license_usage.log" type=usage idx="windows" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals
If the above is not working for you, can you check job inspector and see what's the final search when you replace idx=*
Able to see result for both
index=_internal source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals
And
index=_internal source="*license_usage.log" type=usage idx="windows" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals
If the above is not working for you, can you check job inspector and see what's the final search when you replace idx=*
Than you for the answer !
This is strange, there is a difference between the total and the DMC :
SH query : 925 GB
DMC : 909 GB