Splunk Search

How to check the total consumption out of the 500MB provided by free splunk?

hishamjan
Explorer

Hi,

 

In my production environment, I have two Asterisk Servers installed where one of them caters to 95% of the data while the other caters only 5%.

I successfully installed Splunk Universal Forwarders on my two Asterisks and was able to index data from the 5% server. Now, I want to index similar data from the 95% server as well but, I'm not sure how much quota has been consumed so far out of the 500MB and indexing the 95% server might exceed the limit.

 

Is there a way to figure out how much out of the 500MB is used and how much Is left?

 

Any help will be appreciated.

Labels (4)
0 Karma
1 Solution

aasabatini
Motivator

Try this

 

index=_internal source=*license_usage.log | eval GB=b/1024/1024/1024 | stats sum(GB) by h | sort -sum(GB)

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

View solution in original post

aasabatini
Motivator

Hi,

 

you can check on the menu  settings under the voice licensing.

aasabatini_0-1613639553528.png

Or you can check the consumption by this search:

1
index=_internal source=*license_usage.log type="Usage" splunk_server=* earliest=-1w@d | eval Date=strftime(_time, "%Y/%m/%d") | eventstats sum(b) as volume by idx, Date | eval MB=round(volume/1024/1024,5)| timechart first(MB) AS volume by idx
“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

hishamjan
Explorer

Hi, 

Thank you for your reply. This somewhat answers my question because this query you just shared is showing me the percentage of data consumed by the Indexer itself and not by the Forwarder (95% and 5%) servers.

The Licensing also shows the data consumed today by the indexer as well only.

I'd like to see the data consumed by the forwarders, for now, can we achieve that as well? 

Thanks.

0 Karma

aasabatini
Motivator

Try this

 

index=_internal source=*license_usage.log | eval GB=b/1024/1024/1024 | stats sum(GB) by h | sort -sum(GB)

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

hishamjan
Explorer

Screenshot 2021-02-18 at 5.00.01 PM.png

These are supposed to be added right? Otherwise, it seems as if it is 500MB per h which doesn't make sense to me..

 
 
Tags (1)
0 Karma

aasabatini
Motivator

Sorry but I don't understand your point.

 

you have 500Mb free license for all the forwarders, the search show you the  license consumption by forwarder,  if you sum your values you have a total of  less than 300 Mb.

 

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

hishamjan
Explorer

Thanks a lot, I've got your point

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...