Splunk® App for Chargeback

Use the Splunk App for Chargeback

Acrobat logo Download manual as PDF

Acrobat logo Download topic as PDF

Prerequisites for using Splunk App for Chargeback

Install the following apps on the same Search Head or Search Head Cluster you are intending to use the Splunk App for Chargeback from:

Required Apps

Splunk App for Lookup File Editing. This App is necessary to edit and manage the App lookup files.

Optional Apps

Splunk Machine Learning Toolkit (MLTK).

You must install the Python for Scientific Computing Add-on (listed below) before installing the Machine Learning Toolkit:

The App uses MLTK to forecast search and storage usage. The dashboards alternatively have panels that use the predict command instead. This command does not require MLTK and is available in every Splunk deployment. The Splunk Machine Learning Toolkit, however, contains custom visualizations that are very important in forecasting. Also, the App uses a unique algorithm called the State Space Forecast, which is a forecasting algorithm for time series data in the MLTK and based on Kalman filters. These methods can be considered subsets of features such as local level (an average of recent values), trend (a slope of a line that fits through recent values), seasonality (repeating patterns), etc. Making MLTK more robust than the predict command for serious forecasting, which is the reason we strongly recommend it.

Splunk Cloud customers may need to open a support case to have MLTK installed in their stack if SSAI didn't succeed.

Summary Index

Create a summary index that the Chargeback App will use. The default is chargeback_summary, and it's recommended to set the retention to at least 400 days .

Last modified on 14 October, 2022
Overview of Splunk App for Chargeback
Install or upgrade Splunk App for Chargeback

This documentation applies to the following versions of Splunk® App for Chargeback: current

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters