All Apps and Add-ons

License manager not reporting past 30 days (6.6.4)

halbeisendv
Path Finder

The License Manager server does not report past 30 days. The DMC, on a different server, reports satisfactorily and when I grab the SPL from the LM and run it on the Search Head Cluster the results are as expected. We have already ensured followed the guidance in https://docs.splunk.com/Documentation/Splunk/6.6.4/Admin/LicenseUsageReportViewexamples. Help/guidance is appreciated.

alt text

And, we verified are settings with the boundaries of these recommendations
alt text

0 Karma

Vijeta
Influencer

@halbeisendv Have you tried below query, you can run it on search head.

index=_internal source=*license_usage.log type=Usage host=<your license master>
0 Karma

jkat54
SplunkTrust
SplunkTrust

Does the license master have any search peers? Pretend its trying to be a search head and follow this guidance:

https://docs.splunk.com/Documentation/Splunk/7.3.0/DistSearch/Configuredistributedsearch

halbeisendv
Path Finder

Thank you for your response, but that was not the resolution to the problem we are experiencing.

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

The links copied in are more related to the fact that _internal and thus license_usage.log is only retained for 30 days and then it's buckets freeze by default. So that would be why you can't retrieve license info for days <30 days out. Can you run any searches from the license master?

0 Karma

halbeisendv
Path Finder

This problem is that the License Manager Server will not display license utilization for the past 30 days. Yes, I can run searches from the License Manager. Thank you for your response and assistance.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...