Hi All,
I was trying to check the license usage for last 30days and the logs where not available in internal index. Previous employer has deployed a configuration in /local/search/inputs.conf to index the logs into "main" index. But when i check the logs are not even available there. I was able to see the configuration being monitored when i tried "./Splunk list monitor". But was not able to find the logs. Please help me troubleshoot in finding the license usage logs.
↧