Monitoring Splunk

License Consumption Report Breakdown

shocko
Contributor

 I have Splunk 8.0.5:

  • One cluster master
  • One Search head
  • Two indexers to host clustered indexes

I would like to create a weekly report showing:

  1. License consumption per index, host, source, sourcetype
  2. License consumption per index and thereafter broken down per host, source, sourcetype

Is there already some canned report for this (licensing dashboard?) or would anyone have a custom query?

Labels (2)
0 Karma
1 Solution

saravanan90
Contributor

1. Query to get the license usage per day for index(idx), source(s), sourcetype(st) , host(h) can be pulled from license_usage file. Use the values mentioned in brackets in the timechart.

For each index:

index=_internal host=licenseserver source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = idx | timechart span=1d sum(MB) by idx limit=0  

2. To further drilldown. We can use the below query but this will calculate by going through each events.

index=* | eval esize=len(_raw) | stats sum(esize) as size by index host source sourcetype | eval size_in_GB=(size/1024/1024/1024)

View solution in original post

saravanan90
Contributor

1. Query to get the license usage per day for index(idx), source(s), sourcetype(st) , host(h) can be pulled from license_usage file. Use the values mentioned in brackets in the timechart.

For each index:

index=_internal host=licenseserver source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = idx | timechart span=1d sum(MB) by idx limit=0  

2. To further drilldown. We can use the below query but this will calculate by going through each events.

index=* | eval esize=len(_raw) | stats sum(esize) as size by index host source sourcetype | eval size_in_GB=(size/1024/1024/1024)

shocko
Contributor

Thanks for the reply! Just what I needed and much appreciated. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you looked at the Monitoring Console?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...