Installation

Real-time License Monitoring Search Error

mchandx
Path Finder

Hello,

I am writing a search to integrate with my dashboard.

Goal:

Display current license usage in megabytes as an integer in a "Single Value" type graph.

Error:

When I run the search, I get "N/A" back.

Current Search:

index=internal source=metrics.log group=per_index_thruput series!= | eval totalMB = kb/1024 | chart sum(totalMB) as total

Any help is appreciated!

0 Karma
1 Solution

mchandx
Path Finder

Believe that I may have this resolved.

index=_internal source=*metrics.log group=per_index_thruput series!=_* | eval totalMB = kb/1024 | chart sum(totalMB) as total

View solution in original post

ziegfried
Influencer

There are 2 alternatives to show the current (today's) license usage:

| rest /services/licenser/pools | stats sum(used_bytes) as used | eval used=round(used/1024/1024)

or

index=_internal source=*license_usage.log type=Usage earliest=@d | stats sum(b) as bytes | eval mb=round(bytes/1024/1024) | fields mb
0 Karma

mchandx
Path Finder

Believe that I may have this resolved.

index=_internal source=*metrics.log group=per_index_thruput series!=_* | eval totalMB = kb/1024 | chart sum(totalMB) as total

sdaniels
Splunk Employee
Splunk Employee

Here is an example that works. You can modify accordingly.

index=_internal todaysbytesindexed startdaysago=30 | eval MB_Indexed = todaysBytesIndexed/1024/1024 | stats sum(MB_Indexed) by date_month

There are also several references on this post.

http://splunk-base.splunk.com/answers/4897/how-to-determine-daily-license-usage-in-gb

0 Karma

mchandx
Path Finder

I have tried this before as this is what is in the documentation, but it displays the incorrect information.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...