Reporting

License Usage - Previous 30 days - no results are found

monteirolopes
Communicator

Hi,

I'm running the "License Usage - Previous 30 days" report and no results are found!
When I run the "License Usage - Today" report, information is displayed.
In the filter it is possible to view the pools, however, no information is displayed.
Is there any specific configuration missing?

In my environment, I have 3 instances:
Machine 1: search head, deployment server, license master
Machine 2: Indexer 1
Machine 3: Indexer 2

I use the distributed search architecture.

Reference link: https://answers.splunk.com/answers/113466/license-usage-past-30-days-dont-work.html

alt text

Thanks.

0 Karma
1 Solution

dgrubb_splunk
Splunk Employee
Splunk Employee

Is machine 1 configured to send its internal logs to the indexers?

View solution in original post

dgrubb_splunk
Splunk Employee
Splunk Employee

Is machine 1 configured to send its internal logs to the indexers?

monteirolopes
Communicator

Now my indexers are receiving machine 1 internal logs, however, no results are found in report "License Usage - Previous 30 days".

Is there any specific configuration missing?

0 Karma

monteirolopes
Communicator

It works! The RolloverSummary event had not yet been created.

Reference: http://docs.splunk.com/Documentation/Splunk/6.6.2/Admin/AboutSplunksLicenseUsageReportView

"These panels all use data collected from license_usage.log, type=RolloverSummary (daily totals). If your license master is down at its local midnight, it will not generate a RolloverSummary event for that day, and you will not see that day's data in these panels."

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...