Security

Can I email a licensing alert before it becomes a violation

BobM
Builder

With the latest versions of splunk we have licensing alerts that warn you are approaching a licensing limit and advising you to correct it before midnight but you need to be logged on to see them. Is there a way of making these alerts email me so I have a chance to do this before I get the violation?

I have seen plenty of searches for violations and have seen a search in the Deployment Monitor app for throughput volumes per pool but none that can compare this with the current pool size and alert if it is approaching or over.

hartfoml
Motivator

I have the Search code you need here.
link text

I am still waiting for one peace of help on this.

Read my post to get the code

0 Karma

BobM
Builder

Thanks but it isn't quite what I wanted.

Your search finds data indexed for the day but doesn't compare this to the license pools. I want something dynamic I can put on multiple servers without having to check which pool they are in and what size it is.

PS I answered the date problem.

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...