Installation

Is there a way to send an automated alert for various types of licensing violations?

sjwone
Explorer

Is there a way to send an automated alert for various types of licensing violations. It would be useful to get an automated alert when certain high water marks are reached, i.e. 90% used. And also get alerts with the maximum has been exceeded.

Labels (1)
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Yes. If you are using Splunk 6.0, you can set an alert for any of the searches in the License Usage Report View. See Use the License Usage Report View in the Admin Manual. If you are using Splunk 5.x, install the Splunk on Splunk app and you will have access to the same views for your Splunk 5.x installation.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Yes. If you are using Splunk 6.0, you can set an alert for any of the searches in the License Usage Report View. See Use the License Usage Report View in the Admin Manual. If you are using Splunk 5.x, install the Splunk on Splunk app and you will have access to the same views for your Splunk 5.x installation.

jlaw
Splunk Employee
Splunk Employee

Starting in version 6.2, Splunk Enterprise ships with a few preconfigured alerts (including one for license usage) that you can enable in the distributed management console. Read about Platform alerts in the Admin Manual.

awurster
Contributor

i don't like this approach. splunk needs to have alert "channels" or some other sort of groups of issues / alerts etc more easily subscribed to. without it - the tool remains extremely difficult to use out-of-box. doesn't look like major strides in usability are being made in this department.

bailmon
Explorer

Amen... Seconded !

hexx
Splunk Employee
Splunk Employee

When you say "license server", you mean a Splunk instance running as a license master, right?

0 Karma

stefanlasiewski
Contributor

We use Splunk 5. Our license is stored on a license server. Will Splunk on Splunk allow me to view the License Usage and can I configure it to send alerts?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...