Splunk search for Disk space used by _internal index
Copy
index=_internal source=*license_usage.log type=Usage | eval gb=round(b/1024/1024/1024,4) | stats sum(gb) as GB by host
This is a Splunk search to find the amount of disk space used by Splunk's internal index. The search will separate disk usage by host.