Reporting

License Utilization Report for long time

anandhalagarasa
Path Finder

Hi Team,

We have allocated 500GB of data per day to index in our environment but everyday the utilization is getting crossed more than 500GB and we have deployed Splunk 6.5 version installed in our environment so generally i can able to pull the report only for last 30 days in our License Usage report which has been configured based on Index, Sourcetype & Host information.

But now we want to analyse the trend for last 1 year based on Sourcetype, Index and Host information so that if there is a real need then we will purchase additional license so can you able to help with a search query with the below mentioned key points:

--> We need to pull the license utilization report for last 1 year something like that out of 500 GB how much license is getting utilized every day.

-->Also we want to segregate the license utilization based on Host, Source and Sourcetype.

So it would be really helpful if you can able to provide me the search query or a way to extract the report.

Tags (1)
0 Karma

mayurr98
Super Champion

Hey @anandhalagarasan

you are asking something which is already provided by splunk itself.
On the license Master go to Settings » Licensing » License Usage Reporting » Previous 30 days » Split by Sourcetype/host/Source

The very first panel will be your answer. open in search and get the query.
The query is

index=_internal 
     [ `set_local_host`] source=*license_usage.log* type="Usage" 
 | eval h=if(len(h)=0 OR isnull(h),"(SQUASHED)",h) 
 | eval s=if(len(s)=0 OR isnull(s),"(SQUASHED)",s) 
 | eval idx=if(len(idx)=0 OR isnull(idx),"(UNKNOWN)",idx) 
 | bin _time span=1d 
 | stats sum(b) as b by _time, pool, s, st, h, idx 
 | timechart span=1d sum(b) AS volumeB by st fixedrange=false 
 | join type=outer _time 
     [ search index=_internal 
         [ `set_local_host`] source=*license_usage.log* type="RolloverSummary" earliest=-1y@y 
     | eval _time=_time - 43200 
     | bin _time span=1d 
     | stats latest(stacksz) AS "stack size" by _time] 
 | fields - _timediff 
 | foreach * 
     [ eval <<FIELD>>=round('<<FIELD>>'/1024/1024/1024, 3)]

Modify the time period as per your requirement.
My advice is to create a report of this query and do a report acceleration for faster results.
let me know if this helps!

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...