Monitoring Splunk

Keep track of Free Splunk 500MB limit

elliotholden
New Member

Is there a way I can keep track of the 500MB limit on the Free Splunk to where I can stop Indexing when I get close to 500MB?

0 Karma

jpolvino
Builder

I'd love to see an answer as well, since I'm running the same at home.

The hack I have so far is this, which is probably wrong:
index=_internal source="/opt/splunk/var/log/splunk/license_usage.log"
| stats sum(b) AS bSum first(poolsz) AS poolSz by idx

I imagine you can set up an alert when bSum is close to poolSz?

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...