Hello,
I am writing a search to integrate with my dashboard.
Goal:
Display current license usage in megabytes as an integer in a "Single Value" type graph.
Error:
When I run the search, I get "N/A" back.
Current Search:
index=internal source=metrics.log group=per_index_thruput series!= | eval totalMB = kb/1024 | chart sum(totalMB) as total
Any help is appreciated!
Believe that I may have this resolved.
index=_internal source=*metrics.log group=per_index_thruput series!=_* | eval totalMB = kb/1024 | chart sum(totalMB) as total
There are 2 alternatives to show the current (today's) license usage:
| rest /services/licenser/pools | stats sum(used_bytes) as used | eval used=round(used/1024/1024)
or
index=_internal source=*license_usage.log type=Usage earliest=@d | stats sum(b) as bytes | eval mb=round(bytes/1024/1024) | fields mb
Believe that I may have this resolved.
index=_internal source=*metrics.log group=per_index_thruput series!=_* | eval totalMB = kb/1024 | chart sum(totalMB) as total
Here is an example that works. You can modify accordingly.
index=_internal todaysbytesindexed startdaysago=30 | eval MB_Indexed = todaysBytesIndexed/1024/1024 | stats sum(MB_Indexed) by date_month
There are also several references on this post.
http://splunk-base.splunk.com/answers/4897/how-to-determine-daily-license-usage-in-gb
I have tried this before as this is what is in the documentation, but it displays the incorrect information.