Installation

How to find license usage by indexes?

sunnyparmar
Communicator

Hi,

I have made one search for finding the license usages for indexes that is given below.

index=_internal source=*license_usage.log type=usage (idx=*) | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

Now the issue is if I pass through any index name to idx parameter, then it is giving result for the particular index, but when I am using * for enlisting all indexes, then it is giving "no result found".

Please give suggestions and help me to sort out this issue.

Thanks in advance...

Labels (1)
0 Karma
1 Solution

renjith_nair
Legend

Able to see result for both

index=_internal source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

And

index=_internal source="*license_usage.log" type=usage idx="windows" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

If the above is not working for you, can you check job inspector and see what's the final search when you replace idx=*

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

Able to see result for both

index=_internal source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

And

index=_internal source="*license_usage.log" type=usage idx="windows" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

If the above is not working for you, can you check job inspector and see what's the final search when you replace idx=*

---
What goes around comes around. If it helps, hit it with Karma 🙂

Julian_Gudiel_S
Explorer

Than you for the answer !

This is strange, there is a difference between the total and the DMC :

SH query : 925 GB
DMC : 909 GB

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...