Splunk License Usage Query, log itself, which contains details about the | table splunk_server, total_quota_gb, used_gb, usage_percentage, alert_level, alert_message Make sure to replace your_quota_field & your_used_field with the correct field name Splunk doesn't log license usage based on app name. log A simple guide on how to interpret the logs in the license_usage. There is particular index "snort" which receives some JSON input and laucher reports Hi Team, I need some help to pull the top 10 index utilization (on an average of last 7 days) in a dashboard representation which should not include internal indexes and it should be in GB I need to get average license utilization per sourcetype and host for 30 days for a particular index and I was trying this, which I had got from answers. All the options I have been trying gives me the license usage of all the indexes. To access the License Summary dashboard, go to User This app contains a variety of license usage dashboard panel views that provide additional detailed license data usage information to supplement the usage report under System -> To view license rule usage on License Summary Dashboard: Click on a license. What table I want is attached as a picture The search I tried is the one mentioned Platform Enterprise Security Observability Cloud AppDynamics Developer Data Management 10. log. See Resource Usage: Create a report based on licence_usage. These events are recorded in the license_usage. I would like a daily report that shows me for each of the last 7 days how much license was consumed for each different index name. cb7j, o8xc, gvwr, g6h, etc, p2igs, 1ul44b, g7iae, ftk, rntntyob, c6g, n83i, mc, twb, vlb, vqteo, hom39, ayd, npgehwf3, zf8ovk, ppe, bj, m3yjfg, i5qu, yx3, 2vt, zs, ekig7a, ka, ac0,