Troubleshoot the license usage report view
No results in Previous 30 Days tab
If the panel is empty, the Splunk Enterprise instance acting as the license master (LM) is not finding any licensing events. These events are recorded in the license_usage.log file, and are ingested and stored in the
internal index. Here are some scenarios that might cause the issue:
- The LM instance is not configured to search the indexers or cluster peers. For instructions on configuring the LM to search indexers or peer nodes, see Add search peers to the search head.
- The LM instance stopped ingesting its local Splunk Enterprise log files. Use the
btoolcommand to check the default Splunk Enterprise log monitor
[monitor://$SPLUNK_HOME/var/log/splunk]and verify it is enabled. For examples of
btooluse, see Use btool to troubleshoot configurations.
A gap might appear in the data if the LM was unavailable at midnight, when license reconciliation occurs.
Single-source type license limitations
An instance that has both a single-source type license and an Enterprise license does not always show accurate information.
About the Splunk Enterprise license usage report view
About the app key value store
This documentation applies to the following versions of Splunk® Enterprise: 8.1.0