Splunk Enterprise

Splunk License Usage Report - Max license usage per Index per day showing the peak day per index

SamHTexas
Builder

Please help me fix this SPL to produce the license usage listed above. Thx a million

This is not working for me:

index="_internal"

| stats sum(GB) as A by Date, idx

| eventstats max(A) as B by idx

| where A=B

| dedup A idx

| sort idx

| table Date,A idx

 

Tags (1)
0 Karma
1 Solution

alonsocaio
Contributor

Not so sure, but I guess this query returns only indexes that had used any license on the time range your are searching. If the index didn't receive any data on this time range It won't be returned by the license usage log.

View solution in original post

alonsocaio
Contributor

Hi @SamHTexas, I am not sure if this is what you are looking for, but take a look at the following query:

index="_internal" source="/opt/splunk/var/log/splunk/license_usage.log" type="Usage" 
| eval GB=b/1024/1024/1024 
| bin _time span=1d 
| stats sum(GB) as A by _time, idx 
| eventstats max(A) as B by idx 
| where A=B 
| dedup A idx 
| sort idx 
| table _time,A idx

 I used your base stats, but changed some of the fields on the main query.

0 Karma

SamHTexas
Builder

This is super. But not sure why it does not show all my indexes? Any ideas?

Tags (1)
0 Karma

alonsocaio
Contributor

Not so sure, but I guess this query returns only indexes that had used any license on the time range your are searching. If the index didn't receive any data on this time range It won't be returned by the license usage log.

Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...