Splunk Search

How to search the license usage per index per department?

arjangoos
Path Finder

I want the license usages per index per department.

department 1 has indexes:

idx             volume
acc_jboss       100
prod_jboss      150
test_jboss      50

department 1 volume is 300

department 2 has indexes

idx             volume
prod_network    1000
acc_network     509
test_network    100

department 2 volume is 1609

0 Karma

somesoni2
Revered Legend

Step 1: Create a lookup table file, say dept_index_lookup.csv with field department,index

department,index
...................................
dept1,acc_jboss
dept1,prod_jboss
dept1,test_jboss
dept2,prod_network
dept2,acc_network
dept2,test_network

Step 2 : Search License usage search like this

index=_internal source=*license_usage.log type=usage | stats sum(b) as usageGB by idx | eval usageGB=round(usage/1024/1024/1024,2)  | rename idx as index | lookup dept_index_lookup.csv index OUTPUT department | table department index usageGB
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...