you can run below query in your CMC. | rest splunk_server_group=* /services/licenser/pools | eval total_quota_gb = round(your_quota_field / (1024 * 1024 * 1024), 2) | eval used_gb = round(your_used_field / (1024 * 1024 * 1024), 2) | eval usage_percentage = round((used_gb / total_quota_gb) * 100, 2) | table splunk_server, total_quota_gb, used_gb, usage_percentage | eval alert_level = case( usage_percentage > 90, "Critical", usage_percentage >= 80, "High", usage_percentage >= 70, "Medium", true(), "Normal" ) | eval alert_message = case( usage_percentage > 90, "License usage has crossed critical threshold at " . usage_percentage . "%. Immediate attention required!", usage_percentage >= 80, "License usage has reached " . usage_percentage . "%. Please take immediate action.", usage_percentage >= 70, "License usage has reached " . usage_percentage . "%. Please take action.", true(), "License usage is within normal range." ) | where usage_percentage > 70 | table splunk_server, total_quota_gb, used_gb, usage_percentage, alert_level, alert_message Make sure to replace your_quota_field & your_used_field with the correct field name representing the license quota in your Splunk Cloud environment.
... View more