Installation

Why is the Splunk License Usage report only showing daily usage data and why are all internal indexes empty?

BBakkenes
Explorer

Hello Splunkers,

We have a problem with our Splunk installation. Its a simple platform, Splunk 6.2 on one computer running Ubuntu Linux.
The problem we are experiencing is that its not possible to read out license usage report. Daily usage and percentage is working correctly. Even if we show the license report the today tab is working, but when we switch to the Previous 30 days tab its not generating anything.

I've looked up the _internal index, but it's empty.

Also I tried the following steps:

  • Installed new version of Splunk and copied etc settings needed to run with the same settings as before
  • We have the Splunk database on a different location, after new installation switched to the new location the indexes started with an underscore were disabled, so we enabled them again
  • After that we cleaned the _internal and _audit database from the CLI

But still there is no data in all the indexes starting with an underscore.

Does anyone have a clue?

Labels (2)
0 Karma
1 Solution

BBakkenes
Explorer

Splunk support figured this out, the admin role wasn't allowed to be viewed by the users.

By trying to search | dbinspect index=_internal they found that the index was working correct.

View solution in original post

BBakkenes
Explorer

Splunk support figured this out, the admin role wasn't allowed to be viewed by the users.

By trying to search | dbinspect index=_internal they found that the index was working correct.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...