Splunk search for License usage by pool
index=_internal source=*license_usage.log* type=Usage earliest=-24h| timechart span=1h sum(b) as Volume by pool | eval Volume = round(bytes/1024/1024/1024,4) | rename Volume as "Volume (GB)"
This Splunk search will provide the volume of Splunk license usage separated out by pool. By default the search will show license usage over the last 24 hours (from the time that the search is run)