Monitoring Splunk

License Usage doesn't show after 30 days

jshill103
New Member

My manager asked me to get him license usage for the last year to show growth and justify an upgrade.

I get data for the past 30 days but nothing after that.

Any tips?

0 Karma

DavidHourani
Super Champion

Hi @jshill103,

That's normal because the default frozenTimePeriodInSecs for the _internal index is 30 days which means the maximum you can go back and search there is 30 days, anything older than that gets archived or deleted if you don't have an archiving policy.

You can find that configuration here $SPLUNK_HOME/etc/system/default/indexes.conf, under the [_internal] stanza.

You can increase that limit if needed but it won't bring back the older data.

Cheers,
David

0 Karma

Vijeta
Influencer

You can use _internal index to search on license usage like below, do a timechart based on idx or st and give the time range as what you need

index=_internal source=*license_usage.log type=Usage

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...