Splunk® Enterprise

Admin Manual

Splunk Enterprise version 9.0 will no longer be supported as of June 14, 2024. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.

Troubleshoot the license usage report view

No results in Previous 30 Days tab

If the panel is empty, the Splunk Enterprise instance acting as the license manager can not find any licensing events. These events are recorded in the license_usage.log file, and are ingested and stored in the internal index. Here are some scenarios that might cause the issue:

  • The license manager instance is not configured to search the indexers or cluster peers. For instructions on configuring the license manager to search indexers or peer nodes, see Add search peers to the search head.
  • The license manager instance stopped ingesting its local Splunk Enterprise log files. Use the btool command to check the default Splunk Enterprise log monitor [monitor://$SPLUNK_HOME/var/log/splunk] and verify it is enabled. For examples of btool use, see Use btool to troubleshoot configurations.

A gap might appear in the data if the license manager was unavailable at midnight, when license reconciliation occurs.

Single-source type license limitations

An instance that has both a single-source type license and an Enterprise license does not always show accurate information.

Last modified on 13 August, 2021
About the Splunk Enterprise license usage report view   About the app key value store

This documentation applies to the following versions of Splunk® Enterprise: 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.3.0, 9.3.1

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters