Installation

Real-time License Monitoring Search Error

mchandx
Path Finder

Hello,

I am writing a search to integrate with my dashboard.

Goal:

Display current license usage in megabytes as an integer in a "Single Value" type graph.

Error:

When I run the search, I get "N/A" back.

Current Search:

index=internal source=metrics.log group=per_index_thruput series!= | eval totalMB = kb/1024 | chart sum(totalMB) as total

Any help is appreciated!

0 Karma
1 Solution

mchandx
Path Finder

Believe that I may have this resolved.

index=_internal source=*metrics.log group=per_index_thruput series!=_* | eval totalMB = kb/1024 | chart sum(totalMB) as total

View solution in original post

ziegfried
Influencer

There are 2 alternatives to show the current (today's) license usage:

| rest /services/licenser/pools | stats sum(used_bytes) as used | eval used=round(used/1024/1024)

or

index=_internal source=*license_usage.log type=Usage earliest=@d | stats sum(b) as bytes | eval mb=round(bytes/1024/1024) | fields mb
0 Karma

mchandx
Path Finder

Believe that I may have this resolved.

index=_internal source=*metrics.log group=per_index_thruput series!=_* | eval totalMB = kb/1024 | chart sum(totalMB) as total

sdaniels
Splunk Employee
Splunk Employee

Here is an example that works. You can modify accordingly.

index=_internal todaysbytesindexed startdaysago=30 | eval MB_Indexed = todaysBytesIndexed/1024/1024 | stats sum(MB_Indexed) by date_month

There are also several references on this post.

http://splunk-base.splunk.com/answers/4897/how-to-determine-daily-license-usage-in-gb

0 Karma

mchandx
Path Finder

I have tried this before as this is what is in the documentation, but it displays the incorrect information.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...