My manager asked me to get him license usage for the last year to show growth and justify an upgrade.
I get data for the past 30 days but nothing after that.
Any tips?
Hi @jshill103,
That's normal because the default frozenTimePeriodInSecs
for the _internal
index is 30 days which means the maximum you can go back and search there is 30 days, anything older than that gets archived or deleted if you don't have an archiving policy.
You can find that configuration here $SPLUNK_HOME/etc/system/default/indexes.conf
, under the [_internal]
stanza.
You can increase that limit if needed but it won't bring back the older data.
Cheers,
David
You can use _internal index to search on license usage like below, do a timechart based on idx or st and give the time range as what you need
index=_internal source=*license_usage.log type=Usage