Installation

Real-time License Monitoring Search Error

mchandx
Path Finder

Hello,

I am writing a search to integrate with my dashboard.

Goal:

Display current license usage in megabytes as an integer in a "Single Value" type graph.

Error:

When I run the search, I get "N/A" back.

Current Search:

index=internal source=metrics.log group=per_index_thruput series!= | eval totalMB = kb/1024 | chart sum(totalMB) as total

Any help is appreciated!

0 Karma
1 Solution

mchandx
Path Finder

Believe that I may have this resolved.

index=_internal source=*metrics.log group=per_index_thruput series!=_* | eval totalMB = kb/1024 | chart sum(totalMB) as total

View solution in original post

ziegfried
Influencer

There are 2 alternatives to show the current (today's) license usage:

| rest /services/licenser/pools | stats sum(used_bytes) as used | eval used=round(used/1024/1024)

or

index=_internal source=*license_usage.log type=Usage earliest=@d | stats sum(b) as bytes | eval mb=round(bytes/1024/1024) | fields mb
0 Karma

mchandx
Path Finder

Believe that I may have this resolved.

index=_internal source=*metrics.log group=per_index_thruput series!=_* | eval totalMB = kb/1024 | chart sum(totalMB) as total

sdaniels
Splunk Employee
Splunk Employee

Here is an example that works. You can modify accordingly.

index=_internal todaysbytesindexed startdaysago=30 | eval MB_Indexed = todaysBytesIndexed/1024/1024 | stats sum(MB_Indexed) by date_month

There are also several references on this post.

http://splunk-base.splunk.com/answers/4897/how-to-determine-daily-license-usage-in-gb

0 Karma

mchandx
Path Finder

I have tried this before as this is what is in the documentation, but it displays the incorrect information.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...