Splunk® App for Chargeback

Use the Splunk App for Chargeback

Acrobat logo Download manual as PDF

Acrobat logo Download topic as PDF

Overview of Splunk App for Chargeback

The Splunk App for Chargeback helps customers understand Splunk Cloud or Splunk Enterprise usage by business hierarchy. Starting at the highest level, Business Units (B-Units) are comprised of departments, which are composed of users.


Splunk App for Chargeback provides an easy-to-use experience to analyze how internal business units are leveraging Splunk. This app provides the framework necessary for Chargeback and/or Showback use cases for:

  1. Search Resource Usage (SRU)
  2. Active Searchable Storage: Splunk Cloud Dynamic Data Active Searchable Storage (DDAS) and Splunk Enterprise Storage usage
  3. Dynamic Data Active Archive (DDAA): Splunk Cloud only.
  4. Dynamic Data Self-Storage (DDSS): Splunk Cloud DDSS or Splunk Enterprise GCP or AWS S3 bucket.

The app provides the following functionalities to all Splunk customers:

  • Framework for customers to build their own Chargeback and/or Showback models [Accounting and Utilization respectively]
  • The means to determine how many SRUs are allocated towards a company's business units, departments, and users associated with them [Accounting]
  • The means to automatically determine how Splunk resources are being used by the various business units [Utilization]
  • Ability to drill-down and break down the usage from a business level or user activity
  • Ability to forecast SRU usage for the entire organization or by business unit using Splunk Machine Learning
  • Accurately maintains up-to-date list of identities along with corresponding Business Units & Department information by indexing the data from sources like DB Connect, Active Directory, and several others
Last modified on 14 October, 2022
Release notes for Splunk App for Chargeback
Prerequisites for using Splunk App for Chargeback

This documentation applies to the following versions of Splunk® App for Chargeback: current

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters