Reporting

How to get avg license per host for specific indexes

a212830
Champion

I have a request to determine the average license usage per host, for a few selected indexes, on a daily basis. Is there a way to do this?

0 Karma

harsmarvania57
Ultra Champion

Hi,

Use below query to find per day license for every host which is sending to INDEX_A or INDEX_B

index=_internal host=LICENSE_SERVER source=*license_usage.log* (idx=INDEX_A OR idx=INDEX_B) | bin span=1d _time | stats sum(b) as bytes by h | eval GB=((bytes/1024)/1024)/1024
0 Karma

a212830
Champion

Thanks. Should have been more specific, in addition to the host detailed info, a summary that shows the final average across all of them.

0 Karma

harsmarvania57
Ultra Champion

Do you mean average of all hosts license usage then try below query

index=_internal host=LICENSE_SERVER source=*license_usage.log* (idx=INDEX_A OR idx=INDEX_B) | bin span=1d _time | stats sum(b) as bytes by h | eventstats avg(bytes) as avg_bytes

EDIT: Updated query.

0 Karma

a212830
Champion

I want to calculate how much the average endpoint sends for these paticular indexes.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Based on the questions you've asked, I think you've got the answer here already.

In the license_usage.log the h is the host and idx is the indexes. So you're just doing stats sum(b) by h, idx.

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...