Is it possible to calculate the license usage for specific events?



is it possible to calculate the license usage in GB grouped by specific events?
Let's say I want to know the usage by the parameter eventName. If no eventName is set, I want to use the sourcetype.
So the result should be a calculation grouped by fieldA=coalesce(eventName, soucetype)

Thanks in advance

You can use following query if you want to get details by index name

index=_internal source=*license_usage.log* type=Usage pool="auto_generated_pool_enterprise" | eval GB=b/1024/1024/1024  | stats sum(GB) AS UsageGB by idx | rename idx as Index | eventstats sum(UsageGB) as TotalUsage | eval UsageGB = round(UsageGB,0) | table Index UsageGB | sort -UsageGB | head 10

If you want data via sourcetype, you can use following query:

index="_internal" source="*metrics.log" group="per_sourcetype_thruput" | chart sum(kb) as UsageGB by series | eval UsageGB=round(UsageGB/1024/1024,0) | rename series as SourceType | sort -UsageGB | head 10

I am not sure how you can use event name.


@HeinzWaescher, check out Meta Woot App on Splunkbase. It has a demo video as well. It may be the app that you need:

Following is its description:

The app maintains a near real-time
state table of host, sourcetype and
index metadata. Meta Woot! is accurate
at scale and allows users to instantly
report on host, sourcetype and/or
index together. The app includes
summary based event count trending,
correlation of event volumes against
license and includes compliance
reporting on both data latency and

| makeresults | eval message= "Happy Splunking!!!"
