Reporting

License usage reporting not showing any data

rakeshcse2
New Member

Our Splunk enterprise environment consists of 3 index servers, one search server and one master deployment server.

We are using splunk version 6.2.4.

Can someone please let me know why the deployment server is not showing the license usage graphs ? Please refer attached screen shot.alt text

Tags (1)
0 Karma

kgrigsby_splunk
Splunk Employee
Splunk Employee

Problem:
One particular Splunk report is reporting back with no data, though the dashboard is showing data, and test reports are working as expected.

Problem Description:
Report detailing diskspace and license usage does not send correctly. Many panels report no data when scheduled, but show fine within Splunk, or in a test report.

Recommendation:
Go to 'Access Controls > Users.' Previous customer realized he didn't change the role back to admin after he finished doing some testing on a custom role he was testing out. Switched it over to his LDAP account and it works just fine now.

Solution:
Customer fixed the issue. The report was sending from customer's local account, which did not have admin rights, and therefore could not search/report on the _internal index.

0 Karma

schose
Builder

Hi,

The dashboards are executing index=_internal source=*license_usage.log behind the scenes. I would guess that the instance you are running the dashboards is not definded as a searchhead or it's not forwarding it's own events to the indexers.
Try to run the following search from your search head:

index=_internal source=*license_usage.log type="RolloverSummary" earliest=-30d@d   | eval _time=_time - 43200 | bin _time span=1d | stats latest(b) AS b by slave, pool, _time | timechart span=1d sum(b) AS "volume" fixedrange=false | join type=outer _time [search index=_internal source=*license_usage.log type="RolloverSummary" earliest=-30d@d | eval _time=_time - 43200 | bin _time span=1d | stats latest(stacksz) AS "stack size" by _time] | fields - _timediff  | foreach * [eval <>=round('<>'/1024/1024/1024, 3)]

Regards,

Andreas

0 Karma

rakeshcse2
New Member

The search with index=_internal is working and showing the license usage details, also the server is configured as a search head too under server roles. Still, the graphs are not populating. What else could be missing?

App_->DMC--->Setup-->Serverroles ---Cluster Master
Deployment Server
Indexer
License Master
Search Head

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...