I am writing a search to integrate with my dashboard.
Any help is appreciated!
asked 30 Apr '12, 05:03
Here is an example that works. You can modify accordingly.
index=_internal todaysbytesindexed startdaysago=30 | eval MB_Indexed = todaysBytesIndexed/1024/1024 | stats sum(MB_Indexed) by date_month
There are also several references on this post.
How to determine daily license usage in GB? on Splunk Answers
answered 30 Apr '12, 05:12
There are 2 alternatives to show the current (today's) license usage:
answered 30 Apr '12, 05:41