Splunk® Enterprise

Admin Manual

Splunk Enterprise version 7.1 is no longer supported as of October 31, 2020. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

Troubleshoot the license usage report view

No results in Previous 30 Days tab

If the panel is empty, the Splunk Enterprise instance acting as the license master (LM) is not finding any licensing events. These events are recorded in the license_usage.log file, and are ingested and stored in the internal index. Here are some scenarios that might cause the issue:

  • The LM instance is not configured to search the indexers or cluster peers. For instructions on configuring the LM to search indexers or peer nodes, see Add search peers to the search head
  • The LM instance stopped ingesting its local Splunk Enterprise log files. Use the btool command to check the default Splunk Enterprise log monitor [monitor://$SPLUNK_HOME/var/log/splunk] and verify it is enabled. For examples of btool use, see Use btool to troubleshoot configurations.

A gap might appear in the data if the LM was unavailable at midnight, when license reconciliation occurs.

Single-source type license limitations

An instance that has both a single-source type license and an Enterprise license does not always show accurate information.

Last modified on 04 November, 2020
About the Splunk Enterprise license usage report view   About the app key value store

This documentation applies to the following versions of Splunk® Enterprise: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters