Installation

Can you help me find where I can see the license usage per day in Enterprise Security?

anandhalagarasa
Path Finder

Hi Team,

We have 1 Cluster master, 1 Deployment Master, 8 Indexers and 6 Search Head servers in our environment. In which Licensing is deployed in our Deployment master server and we have bought license for 700 GB per day, for which I am able to see the same in GUI by navigating to Licensing page from Settings in Deployment master GUI. And also, I am able to get the information, such as how much it has been utilized and how much it's still having for the day, and so on.

But we got information stating that we have already have 380 GB of License dedicated for Enterprise Security, but where can I see the License usage per day for ES and how much it's getting utilized and so on in GUI?

Kindly note we have deployed Splunk Enterprise APP separately in a search head server.

So, I need your help to know how can we find a way to show up the ES license used and so on.

Labels (4)

jbrocks
Communicator

Maybe the telemetry.conf is the right file to handle this. You can create this file per App and track its license usage - I do not really know how it works, but maybe it will help you http://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Telemetryconf

0 Karma

broberg
Communicator

don't you see that on the DMC (Monitoring Console ->Indexing)? Or just qith a search string as bellow.

https://answers.splunk.com/answers/4897/how-to-determine-daily-license-usage-in-gb.html

0 Karma

anandhalagarasa
Path Finder

Hi,

Thanks for your response.

I can able to fetch the license usage for Splunk Enterprise but i am more concerned about the Splunk Enterprise Security App. I want to know how to fetch the details usage of Enterprise Security App which we have brought for 380 GB of indexing per day.

0 Karma

broberg
Communicator

Read the docs about the LURV here http://docs.splunk.com/Documentation/Splunk/latest/Admin/LicenseUsageReportViewexamples

Well, you can have a look at the license usage by sourcetype based on the LURV to get the numbers.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...