Getting Data In

REST Calls for license usage

mphalak
New Member

Today I have this search to alert me on license usage going beyond certain threshold:
Search: index=_internal source=*license_usage.log pool="auto_generated_pool_enterprise"| eval GB=b/1024/1024/1024 | stats sum(GB) as current_license_usage_auto_generated_pool_GB by pool

Due to some reasons I am getting wrong results for the above ....How can I change this search to use rest endpoints ??

Tags (2)
0 Karma

yannK
Splunk Employee
Splunk Employee

on 4.3, please specify a type of records, otherwise you may count things twice.

type=Usage

type=RolloverSummary

see the difference here : http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

0 Karma

mphalak
New Member

Thanks I was able to get teh resulst with this search:

| rest /services/licenser/pools | where title= "auto_generated_pool_enterprise" | table used_bytes, title | eval GB=used_bytes/1024/1024/1024

BUT now when I set the same as saved search and try to send alert when GB>1 I see the following error:

DEBUG: search context: user="admin", app="tto_search", bs-pathname="/opt/splunk/etc"
INFO: No matching fields exist
WARN: Unable to fetch REST endpoint '/services/licenser/pools' from ''

ANY IDEA ???

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...