I use the following to show me what my estimated license usage is at the time the search is ran.
I would like to create a chart that looks at the past X days and show me what I used.
index=_internal source=*license_usage.log earliest=@d+30m| eval GB=b/1024/1024/1024 | stats sum(GB) by pool | eval used='sum(GB)' | eval GB_Used_Today=round(used, 0) | fields GB_Used_Today
Before you go creating your own search for license usage, have you checked the available apps out there for license usage?
http://splunk-base.splunk.com/apps/search/?q=license+usage
Please mark as answered if your question has been answered. Thanks!
Yes, the reporting is not accurate.