When was the last time we ingested from this host?
What is the average ingestion(GB) per sourcetype?
Hi @mahendra559 ,
did you already have seen the License consuption searches [Settings -- Licensing -- Usage Report -- Previous 30 days] using the option Split by sourcetype or Split by host?
In addition, you could use the Monitoring Console [Settings -- Monitorig Console] or find in the Splunkbase ( apps.splunk.com ) an App with all the views you need: I use the "Detailed License Monitoring and Alerting for Splunk" ( https://splunkbase.splunk.com/app/3576/ ) but there are also other apps.
Ciao.
Giuseppe