All Apps and Add-ons

license usage alerts

nicco
Explorer

This is the reference that I'm looking at:
http://www.splunk.com/wiki/Community:TroubleshootingIndexedDataVolume

Specifically this search:

index=_internal source=*license_usage* pool="default" | eval GB=b/1024/1024/1024 | stats sum(GB) by pool | where sum(GB) > 0.3

And I get this error:

Error in 'where' command: The 'sum' function is unsupported or undefined.

Relating to this part of the search:

where sum(GB) > 0.3

So, I look up the search manual and there is in fact no sum function to the where command. I've tried a bunch of variations and I'm not getting the expected result.

Can anyone shed any light on where I'm going wrong (and fix the doco)

Thanks.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The correct syntax is either:

index=_internal source=license_usage pool="default" | eval GB=b/1024/1024/1024 | stats sum(GB) by pool | where 'sum(GB)' > 0.3

i.e., single quote sum(GB). It is not a function. It is a variable name that was created by stats. You could also use:

index=_internal source=license_usage pool="default" | eval GB=b/1024/1024/1024 | stats sum(GB) as sumGB by pool | where sumGB > 0.3

Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...