Monitoring Splunk

Keep track of Free Splunk 500MB limit

elliotholden
New Member

Is there a way I can keep track of the 500MB limit on the Free Splunk to where I can stop Indexing when I get close to 500MB?

0 Karma

jpolvino
Builder

I'd love to see an answer as well, since I'm running the same at home.

The hack I have so far is this, which is probably wrong:
index=_internal source="/opt/splunk/var/log/splunk/license_usage.log"
| stats sum(b) AS bSum first(poolsz) AS poolSz by idx

I imagine you can set up an alert when bSum is close to poolSz?

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...