Splunk Search

Why am I unable to search event data for license_usage.log?

srikanth1213
Path Finder

Hi Guys, I am unable to search the event data for license_usage.log , whereas I can see the log file getting updated in the server. kindly help if I have to enable it elsewhere to display in search.

0 Karma
1 Solution

srikanth1213
Path Finder

Hi , We were able to fix the issue by enabling the logging of the directory "$SPLUNK_HOME\var\log\splunk " under data inputs in Splunk UI ..thank you.

View solution in original post

0 Karma

srikanth1213
Path Finder

Hi , We were able to fix the issue by enabling the logging of the directory "$SPLUNK_HOME\var\log\splunk " under data inputs in Splunk UI ..thank you.

0 Karma

PPape
Contributor

Are you in an clustered enviroment or in an single instance enviroment?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

IIRC, your role needs access to the _internal index to read that log.

---
If this reply helps you, Karma would be appreciated.
0 Karma

srikanth1213
Path Finder

Well , I logged in as an admin , and it does has access to _internal index as I am able to search the data when I give index=_internal ...

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...