Monitoring Splunk

License Consumption Report Breakdown

shocko
Contributor

 I have Splunk 8.0.5:

  • One cluster master
  • One Search head
  • Two indexers to host clustered indexes

I would like to create a weekly report showing:

  1. License consumption per index, host, source, sourcetype
  2. License consumption per index and thereafter broken down per host, source, sourcetype

Is there already some canned report for this (licensing dashboard?) or would anyone have a custom query?

Labels (2)
0 Karma
1 Solution

saravanan90
Contributor

1. Query to get the license usage per day for index(idx), source(s), sourcetype(st) , host(h) can be pulled from license_usage file. Use the values mentioned in brackets in the timechart.

For each index:

index=_internal host=licenseserver source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = idx | timechart span=1d sum(MB) by idx limit=0  

2. To further drilldown. We can use the below query but this will calculate by going through each events.

index=* | eval esize=len(_raw) | stats sum(esize) as size by index host source sourcetype | eval size_in_GB=(size/1024/1024/1024)

View solution in original post

saravanan90
Contributor

1. Query to get the license usage per day for index(idx), source(s), sourcetype(st) , host(h) can be pulled from license_usage file. Use the values mentioned in brackets in the timechart.

For each index:

index=_internal host=licenseserver source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = idx | timechart span=1d sum(MB) by idx limit=0  

2. To further drilldown. We can use the below query but this will calculate by going through each events.

index=* | eval esize=len(_raw) | stats sum(esize) as size by index host source sourcetype | eval size_in_GB=(size/1024/1024/1024)

shocko
Contributor

Thanks for the reply! Just what I needed and much appreciated. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you looked at the Monitoring Console?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...