Installation

How to find license usage by indexes?

sunnyparmar
Communicator

Hi,

I have made one search for finding the license usages for indexes that is given below.

index=_internal source=*license_usage.log type=usage (idx=*) | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

Now the issue is if I pass through any index name to idx parameter, then it is giving result for the particular index, but when I am using * for enlisting all indexes, then it is giving "no result found".

Please give suggestions and help me to sort out this issue.

Thanks in advance...

Labels (1)
0 Karma
1 Solution

renjith_nair
Legend

Able to see result for both

index=_internal source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

And

index=_internal source="*license_usage.log" type=usage idx="windows" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

If the above is not working for you, can you check job inspector and see what's the final search when you replace idx=*

Happy Splunking!

View solution in original post

renjith_nair
Legend

Able to see result for both

index=_internal source="*license_usage.log" type=usage idx="*" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

And

index=_internal source="*license_usage.log" type=usage idx="windows" | eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

If the above is not working for you, can you check job inspector and see what's the final search when you replace idx=*

Happy Splunking!

Julian_Gudiel_S
Explorer

Than you for the answer !

This is strange, there is a difference between the total and the DMC :

SH query : 925 GB
DMC : 909 GB

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...