Dears
What are the main differences between calculating SPLUNK daily license from the ready-made query located in SPLUNK master (DMC Alert - Total License Usage Near Daily Quota)
And from using below query:
index=_internal source=*license_usage.log type=Usage
| stats sum(b) as bytes by idx
| eval LicenseUsage_GB = round(bytes/1024/1024/1024,5)
|table idx LicenseUsage_GB
As I found a remarkable differences when using the 2 above ways even when calculating the total available license.
Thanks