Monitoring Splunk

Keep track of Free Splunk 500MB limit

elliotholden
New Member

Is there a way I can keep track of the 500MB limit on the Free Splunk to where I can stop Indexing when I get close to 500MB?

0 Karma

jpolvino
Builder

I'd love to see an answer as well, since I'm running the same at home.

The hack I have so far is this, which is probably wrong:
index=_internal source="/opt/splunk/var/log/splunk/license_usage.log"
| stats sum(b) AS bSum first(poolsz) AS poolSz by idx

I imagine you can set up an alert when bSum is close to poolSz?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...