Hi Team,
I need some help to pull the top 10 index utilization (on an average of last 7 days) in a dashboard representation which should not include internal indexes and it should be in GB so kindly help out with the search query.
And also similarly I need the Splunk License Usage by Host and Sourcetype in a Dashboard view (Last 7 days average data) in GB.
So kindly help out on the same.
Go to the "Cloud Monitoring Console" app, click on the "Indexing" menu, the "License Usage" submenu and poke around. When you find a panel that you like, click the Magnifying Glass icon to "Open in Search" and copy that search.
Go to Settings -> Licensing, Click "usage report", "Previous 60 days". Click the little magnifying glass under the graph to open in search. Adjust the search to your needs.
BTW, indernal indexes do not consume license so your requirement for _not_ including them is not necessary.
Our Splunk is hosted in Cloud (AWS) and managed by Support. So when I logged into the Search Head and navigate to Settings-->Licensing I could see two options.
Licensing --> Switch to Local Manager option.
Local Server Information
Indexer Name
Manager Server URI
Last successful contact time
Messages
And there is no option as Usage Reports so kindly let me know how to pull it.
In Splunk Cloud you should have licensing report(s) available in Cloud Monitoring Console. I'm not on the cloud right now so I'm not able to tell you exactly where it is, but it's there.