index=_internal earliest=-1w latest=now source=license_usage.log type=Usage
| eval s=if(s=="","unknown",s)
| eval h=if(h=="","unknown",h)
| stats sum(b) AS volume_b by st
| eval volume_g=volume_b/1024/1024
| rename st as SourceType
| fields - volume_b
| sort - volume_g
That is odd since it works fine for me. Is this a single server install? https://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume
Thanks. It came back with no data. Tried it on 2 different systems.
Download the SoS app. It should have all the license metrics for you. You will also need the sideview utils app.
Sos has detected that you are running Splunk 6..go to license manager page.
That lists everything, without the ability to drill-down. Is there an available search?