Application: Splunk License Usage

Categories:

Description

This bundle provides a new dashboard which has several widgets that query to help you determine your Splunk license usage total over the past 24 hours as well as usage by host, source, and sourcetype. It contains timecharts to help you understand usage over time and see usage spikes as well as pie charts to help you to figure out which log files, sourcetypes, and hosts Splunk is indexing the most data from.

To install this add-on, download it, move the file to the computer running your Splunk server, and then unpack it into your Splunk instance's etc/bundles folder. Restart your Splunk server to load the add-on, then look for your new "Splunk License" dashboard. You will also see the following new saved searches:

  • kBs Indexed in the Past 24 Hours by Index
  • kBs Indexed in the Past 24 Hours by Host
  • kBs Indexed in the Past 24 Hours by Source
  • kBs Indexed in the Past 24 Hours by Sourcetype
  • Total kBs of Logs Indexed in the Past 24 Hours by Host
  • Total kBs of Logs Indexed in the Past 24 Hours by Source
  • Total kBs of Logs Indexed in the Past 24 Hours by Sourcetype

When you run these saved searches, they automatically generate your reports for the past 24 hours. Just change the time value to cover the timespan you're interested in.

Rating

(6 votes)
Login to rate this Application

Preview Application: