
Troubleshoot the license usage report view
No results in Previous 30 Days tab
A lack of results in the panels of the Previous 30 Days view of the license usage report view indicates that the license master cannot find events from its own $SPLUNK_HOME/var/log/splunk/license_usage.log
file.
This situation typically has one of these causes:
- The license master is configured to forward its events to indexers, but it has not been configured as a search head to those indexers. This is remedied by adding as its search peers all indexers that the license master is forwarding events to.
- The license master is not reading (and therefore, not indexing) events from its own
$SPLUNK_HOME/var/log/splunk
directory. This can happen if the[monitor://$SPLUNK_HOME/var/log/splunk]
default data input is disabled for some reason.
You might also have a gap in your data if your license master is down at midnight.
Single-source type license limitations
An instance that has both a single-source type license and an Enterprise license does not always show accurate information.
PREVIOUS About the Splunk Enterprise license usage report view |
NEXT About the app key value store |
This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 8.0.0, 8.0.1
Feedback submitted, thanks!