Hello, is it possible to search Splunk for list of concurrent searches usage over time by searching internal log?
Similar to this question for daily license usage:
https://answers.splunk.com/answers/68036/daily-license-usage-query.html
Refer to @somesoni2's answer for the same: https://answers.splunk.com/answers/381951/monitor-concurrent-searches.html
index=_internal sourcetype=splunkd source=*metrics.log group=search_concurrency
or use the DMC (after 6.5.0 its called MC)
Converted to answer, because I think it's an answer. 🙂
Also, perhaps to add to that just a tiny bit:
index=_internal sourcetype=splunkd source=*metrics.log group=search_concurrency earliest=-1w
| timechart max(active_hist_searches), max(active_realtime_searches)
Which will show the last week's worth. Do line chart.