Reporting

License Usage Report for 30 days only shows part of the month

chrislibby
Engager

My License Usage Report is missing about half of the last 30 days, no matter what pool or split I look at. It's a simple setup - one server running everything.

0 Karma

jensonthottian
Contributor

That could be because the data could have been already purged for last half.

Go to settings and click on Indexes:
What is the Max size (MB) of entire index set for _internal index??
You will also see a column - Earliest event ..what is the earliest event there?

0 Karma

yannK
Splunk Employee
Splunk Employee

yes the _internal index retention are 30days and 500Mb, so if may have deleted the oldest events already if the size reached 500 in less than one month.

0 Karma

chrislibby
Engager

The max size is 500mb, the current size is 905mb. The earliest event is 6/22/15, and the latest event is 8/21/15 current time. Could it be the size?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...