How long is the license information kept in it's indexer? I need to show a long-term graph of what we've been using, along with a peak value.
The plug-in Splunk-on-Splunk SOS has this pre-built for you, which might save you some work. The option is available from the splash page, the last of the searches on the right hand side. It queries $SPLUNK_HOME/var/log/splunk/license_usage.log.
The option to search 'all time' is supported.
Good luck! 😉