Monitoring Splunk

How to get license usage data for a particular index with a breakdown of usage by a field?

jackiewkc
Path Finder

Hi,

Does anyone know how I can query the license usage of a particular index, breakdown by a field?

Basically I have an index called testindex and there is a field in each event called log_type. I would like to know, on a given date, how much indexed data there is in this index, broken down by log_type. I would expect the output to be something like:

log_type1 10G
log_type2 1.5G
log_type3 0.45G
etc.

Any help will be greatly appreciated.

Thanks.

Regards,
Jackie

1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I fear the license usage logs aren't going to be helpful here, so you may need to go brute force:

index=particular | eval length = length(_raw) | timechart span=1d sum(length) by log_type

If you're going to run this more than once it'll be a good idea to summary index the daily data.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

I fear the license usage logs aren't going to be helpful here, so you may need to go brute force:

index=particular | eval length = length(_raw) | timechart span=1d sum(length) by log_type

If you're going to run this more than once it'll be a good idea to summary index the daily data.

martin_mueller
SplunkTrust
SplunkTrust

Technically they are in characters. Convert before the timechart, so something like this:

... | eval length = length(_raw) / 1048576 | ...

to get the length in megacharacters.

jackiewkc
Path Finder

Thanks Martin

0 Karma

jackiewkc
Path Finder

Thanks a lot for the quick reply, I really appreciate it.

0 Karma

jackiewkc
Path Finder

One quick question. The numbers returned from the query you suggested, are they in bit or byte or Mb? I want to have it set to GB, but when I changed sum(length) to sum(length/1024), it didn't work.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...