Monitoring Splunk

Is there a way to determine Splunk License Usage for a Specific Event Type?

omprakash9998
Path Finder

Hi,

Is there a way to determine Splunk License Usage for a specific event type. 

I used index=_internal source=*license_usage.log* st=abcd to determine the license usage for the entire sourcetype.

To dig in deeper for the specific event type I found articles pointing to use len(_raw) which gives the byte size length of the raw event. I used the below to check if it returns the same from license_usage.log

index="x" sourcetype=abcd | bin _time span=1d | eval size=len(_raw) | stats sum(size) as sizeInBytes by _time | eval GB = sizeInBytes/1024/1024/1024

The numbers do not match. The numbers from len(_raw) are very high when compared to the actual License Usage.

 

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...