Monitoring Splunk

Splunk License Usage by Index or Host or Sourcetype

anandhalagaras1
Contributor

Hi Team,

I need some help to pull the top 10 index utilization (on an average of last 7 days) in a dashboard representation which should not include internal indexes and it should be in GB so kindly help out with the search query.

And also similarly I need the Splunk License Usage by Host and Sourcetype in a Dashboard view (Last 7 days average data) in GB.

 

So kindly help out on the same.

Labels (2)
0 Karma

woodcock
Esteemed Legend

Go to the "Cloud Monitoring Console" app, click on the "Indexing" menu, the "License Usage" submenu and poke around.  When you find a panel that you like, click the Magnifying Glass icon to "Open in Search" and copy that search.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Go to Settings -> Licensing, Click "usage report", "Previous 60 days". Click the little magnifying glass under the graph to open in search. Adjust the search to your needs.

BTW, indernal indexes do not consume license so your requirement for _not_ including them is not necessary.

0 Karma

anandhalagaras1
Contributor

@PickleRick ,

Our Splunk is hosted in Cloud (AWS) and managed by Support. So when I logged into the Search Head and navigate to Settings-->Licensing I could see two options.

 

Licensing --> Switch to Local Manager option.

Local Server Information 

Indexer Name

Manager Server URI

Last successful contact time

Messages 

 

And there is no option as Usage Reports so kindly let me know how to pull it.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

In Splunk Cloud you should have licensing report(s) available in Cloud Monitoring Console. I'm not on the cloud right now so I'm not able to tell you exactly where it is, but it's there.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...