Hi,
We are seeing the sudden spike of the license consumption in our splunk es since last week,
Where do we get to see the all indexes license consumption daily wise,,
what is the cause of this sudden splunk ?
The License Manager can show license usage over time. It can group the usage by index or sourcetype to help you find where the usage is coming from.
Sudden spikes can be normal periodic increases, but often are caused by a new data source or existing source that changed verbosity (turned on DEBUG logging, for instance).
Also sometimes change on the source (like version upgrade) can result in change in log format/level of detail even without changing loglevel (i.e. new software versions logs additional fields in the events).