Monitoring Splunk

How to find out how many license violations have occurred in the last 30 days in Splunk 6.2?

niklucky02
Explorer

I have installed Splunk 6.2 version and it shows a license violation under category 'license_window'. Is there any way we can find out how many violations have occurred in last 30 days in version 6.2?

0 Karma
1 Solution

phadnett_splunk
Splunk Employee
Splunk Employee

The best way to do this is to monitor the 30 day License Usage Report View (LURV) in Settings > LIcensing > Usage Report > Previous 30 Days

View solution in original post

phadnett_splunk
Splunk Employee
Splunk Employee

The best way to do this is to monitor the 30 day License Usage Report View (LURV) in Settings > LIcensing > Usage Report > Previous 30 Days

phadnett_splunk
Splunk Employee
Splunk Employee

@niklucky02 You could use a search like this to see each time a warning occurs for the pool. You have 5 or more warnings in a rolling 30-day period before a violation for the pool occurs.

index=_internal sourcetype=splunkd component=LMStackMgr "A warning has been recorded for all members"

niklucky02
Explorer

Thanks Phadnett! The query worked but it was showing 5 violations whereas my search didn;t lock out. Anyways, I will keep this query as the message is exactly what I was looking for.

niklucky02
Explorer

@phadnett: I see some variations in the number of violations messages that I see under LURV and the reason I posed this question. My question is there a pattern inside splunk logs on the license master server that would help me to see that I have violated 3 times in last 30 days or an alternate splunk query?

0 Karma

niklucky02
Explorer

Violation alerts under licensing tab are not consistent and it seems to retrieve those messages using REST API. Re-framing my earlier question, is there a way to track the number of violations from the splunk logs?

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...