Installation

Splunk license usage by host or indexes top 10

mintughosh
Path Finder

I have wrote a query to find out the license usage by host. But I need to find out the top 10 hosts or indexes in terms of license usage. I have written the following query.

index=_internal source="*license_usage.log" | stats sum(b) as bytes by h | eval MB = round(bytes/1024/1024,1) | rename h as "HOSTNAME" | fields - bytes | rename MB as "License Consumption (MB)"

The above query gives me license usage of all the hosts. I need to find top 10 hosts or indexes.

Tags (1)
0 Karma
1 Solution

dineshraj9
Builder

Sort by consumption and use the top 10 values -

index=_internal source="*license_usage.log" | stats sum(b) as bytes by h | eval MB = round(bytes/1024/1024,1) | rename h as "HOSTNAME" | fields - bytes | rename MB as "License Consumption (MB)" | sort 10 - "License Consumption (MB)"

View solution in original post

0 Karma

mwong
Splunk Employee
Splunk Employee

You can also use "top" command to show the most usage host. Please refer to our below documentation.

https://docs.splunk.com/Documentation/Splunk/6.5.3/SearchReference/Top

0 Karma

dineshraj9
Builder

Sort by consumption and use the top 10 values -

index=_internal source="*license_usage.log" | stats sum(b) as bytes by h | eval MB = round(bytes/1024/1024,1) | rename h as "HOSTNAME" | fields - bytes | rename MB as "License Consumption (MB)" | sort 10 - "License Consumption (MB)"
0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...