@nickhills ,
Thank you for your response.
When i tried to run the following search query in Search & Reporting of Splunk Cloud i can able to see the events and not the stats or visualization for last 30 days and even i tried to run for All time.
(index=_internal source=license_usage.log type="RolloverSummary")
| bin _time span=1d
| stats latest(b) AS b latest(stacksz) AS stacksz by slave, pool, _time
| stats sum(b) AS volumeB max(stacksz) AS stacksz by _time
| eval pctused=round(((volumeB / stacksz) * 100),2)
| timechart span=1d max(pctused) AS "used" fixedrange=false
| where used>90
Similarly I have tried this search query using predict command for last 30 days and the visualization shows as 0 for all the fields. Can i know how it works
(index=_internal source=license_usage.log type="RolloverSummary")
| bin _time span=1d
| stats latest(b) AS b latest(stacksz) AS stacksz by slave, pool, _time
| stats sum(b) AS volumeB max(stacksz) AS stacksz by _time
| eval pctused=round(((volumeB / stacksz) * 100),2)
| timechart span=1d max(pctused) AS "used" fixedrange=false
| predict used
My requirement is that we need to get notified if we use 90% of license usage in a day and also based on the past trends can we able to predict for the future usage that is for March & April 2020.
... View more