Splunk search for License Usage by Sourcetype
Copy
index=_internal source=*license_usage.log type="Usage"
| eval indexname = if(len(idx)=0 OR isnull(idx),"(UNKNOWN)",idx)
```| search st=<insert sourcetype here>```
| timechart span=1d sum(eval(b/pow(1024,3))) by st
This search will display a timechart of Splunk license usage by sourcetype. To filter on specific sourcetype(s) uncomment the "| search st=" line and enter the applicable sourcetype(s).