I have 2 Splunk systems - Prod and QA. Both are running the same version, have the same data before forwarded to them, etc. When I run the Splunk License Usage in Prod, it works fine - I've even added some for 7 and 30 day periods.
But, when I use the license app for QA, every applet is showing the results based on hosts, not source or sourcetype. If I manually run the query for a particular applet in the search screen, it shows hosts across the top, not sourcetype. But, if I look at my main Splunk screen, the sourcetypes are there and seems to be working correctly.
If I execute the query in the search app, I get the same thing - column headings with hosts instead of sourcetypes.
index="_internal" source="/*/metrics.log" per_sourcetype_thruput | timechart sum(kb) by series
What would cause this?
Thanks!
... View more