Monitoring Splunk

License Consumption Report Breakdown

shocko
Contributor

 I have Splunk 8.0.5:

  • One cluster master
  • One Search head
  • Two indexers to host clustered indexes

I would like to create a weekly report showing:

  1. License consumption per index, host, source, sourcetype
  2. License consumption per index and thereafter broken down per host, source, sourcetype

Is there already some canned report for this (licensing dashboard?) or would anyone have a custom query?

Labels (2)
0 Karma
1 Solution

saravanan90
Contributor

1. Query to get the license usage per day for index(idx), source(s), sourcetype(st) , host(h) can be pulled from license_usage file. Use the values mentioned in brackets in the timechart.

For each index:

index=_internal host=licenseserver source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = idx | timechart span=1d sum(MB) by idx limit=0  

2. To further drilldown. We can use the below query but this will calculate by going through each events.

index=* | eval esize=len(_raw) | stats sum(esize) as size by index host source sourcetype | eval size_in_GB=(size/1024/1024/1024)

View solution in original post

saravanan90
Contributor

1. Query to get the license usage per day for index(idx), source(s), sourcetype(st) , host(h) can be pulled from license_usage file. Use the values mentioned in brackets in the timechart.

For each index:

index=_internal host=licenseserver source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = idx | timechart span=1d sum(MB) by idx limit=0  

2. To further drilldown. We can use the below query but this will calculate by going through each events.

index=* | eval esize=len(_raw) | stats sum(esize) as size by index host source sourcetype | eval size_in_GB=(size/1024/1024/1024)

shocko
Contributor

Thanks for the reply! Just what I needed and much appreciated. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you looked at the Monitoring Console?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...