Monitoring Splunk

Can you help me with a License Usage justification Report?


Hi Team,

I am facing a license violation issue,

I have received 4 warnings (29th 30th 31st 1st august) but 2nd and 3rd September there is no violation. But what we are thinking is we don't want to take a risk. To avoid that risk, we are thinking of increasing the license, but before increasing the license, my manager wants justification for why these violations have happened.

So i went to the license usage report and checked for last 30days and in sourcetype "wineventlog:security" consuming more data in Splunk.

Then i compared the logs 26th august (205 gb wineventlog:security) and 31st august (260 gb wineventlog:security) but they want to know why this much of data was used and to know where it came from.

Team can you please help me get this report.

Thanks and regards,
shaik hussain

0 Karma


Start with a count of distinct sources. If someone added several new Windows servers lately then that might explain the extra data being indexed. It's also possible some servers couldn't connect to the indexers for some time and sent in a backlog of events once connections were re-established.

| tstats count where index=_internal sourcetype="wineventlog:security" by host
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...