Installation

Why is the "Daily License Usage" showing incorrect values?

khagan
Path Finder

Hi,

I recently migrated a Splunk instance from a Windows environment to a Linux environment. Since the migration, dashboards on the "License Usage" page have been displaying usage values up to ten times larger than are actually being indexed. There have been no license violations, so this data can't be correct. What might be causing this?

Tags (1)
0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi khagan,

I assume the Splunk instant you migrated is the license master, right? Because if it's a license slave, none of the migration activities matter.

On the license master, please review license_usage.log under SPLUNK_HOME/var/log/ to see what has caused the increased license usage.
You can also use the following searches in Splunk Web to investigate your license consumption issue.

index=_internal component=LicenseUsage* | top type

index=_internal component=Metrics per_index_thruput | eval mb=(kb/1024) | timechart span=1h sum(mb) by series | addtotals

Hope it helps. Thanks!
Hunter

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...