Monitor Splunk Infrastructure Monitoring subscription usage 🔗
Note
This topic describes general aspects of your usage and consumption. For more detailed billing-related queries, contact your Splunk Account Team.
Caution
The information in this topic applies to organizations whose subscription plan is based on the number of hosts or metrics that Splunk Infrastructure Monitoring is monitoring for you. If your organization’s usage is based on the rate at which you send data points to Infrastructure Monitoring (DPM), see Monitor Splunk Infrastructure Monitoring billing and usage (DPM plans only).
Overview 🔗
Admin users in your organization can view the subscription usage information for the organization. The application provides a summary and detailed reports to help you understand and manage the data that Infrastructure Monitoring monitors for you. In addition to counts for hosts and containers, the reports also contain counts for custom, bundled, and high-resolution metrics.
About custom, bundled, and high-resolution metrics 🔗
The following sections describe the different categories of metrics in the metric time series (MTS) that Infrastructure Monitoring collects.
Differences between host, container, bundled, and custom metrics 🔗
Metrics category |
Description |
---|---|
Host and container metrics |
|
Bundled metrics |
|
Custom metrics |
|
Differences between high-resolution metrics and standard-resolution metrics 🔗
Metrics category |
Description |
---|---|
Standard-resolution metrics |
|
High-resolution metrics |
|
Viewing and downloading Infrastructure Monitoring usage reports 🔗
Infrastructure Monitoring usage reports help you understand the amount of data you’re sending. Use these reports to manage your costs and ensure you’re collecting the correct data.
Prerequisites 🔗
To view and download usage reports, you must be an organization admin.
View usage reports 🔗
To view the available usage reports:
Log in to Observability Cloud.
In the left navigation menu, select
.Select the Infrastructure Monitoring tab.
You can see a chart showing your current usage numbers for hosts, containers, custom metrics, and high-resolution metrics. Below the chart, you might see additional charts representing usage trends that you can customize to show different data or different time periods.
Download a usage report 🔗
To view usage reports available for download:
Log in to Splunk Observability Cloud.
In the left navigation menu, select
.Select the Infrastructure Monitoring tab.
Click View detailed usage reports.
Click a report link on the Usage tab or Usage Breakdown tab to download it as a tab-delimited text file. In some browsers, you might have to right-click on a report to save the report.
Note
If you have switched from a DPM-based subscription plan to a plan based on the number of hosts or metrics that Infrastructure Monitoring monitors for you, older reports on the Usage tab indicate that they represent DPM-based data. Reports on the Usage Breakdown tab are not available for dates before changing your subscription.
Monthly usage report 🔗
This report is available on the Usage tab. For each hour within the month (or month to date, for the current month), this report shows the number of hosts and containers monitored and the number of custom metrics and high-resolution metrics sent to Infrastructure Monitoring. This report follows your usage period and uses the month when a usage period starts as the label in the report link. For example, if your usage period begins on the 10th of the month, then a link for ‘March 2022’ covers from March 10 through April 9, 2022.
You can use the monthly usage report to determine whether your usage is in line with your subscription plan. You can use the data to calculate your average usage, how many hours in the month you have been over or under your plan, and by how much.
The report has six columns:
Column |
Description |
---|---|
Date |
Follows the mm/dd/yy format. |
Hour Ending |
Follows the 24 hour hh:mm UTC format. For example, 01:00 indicates the hour from midnight to 1:00 AM UTC. |
# Hosts |
The number of hosts that sent data during the specified hour. |
# Containers |
The number of containers that Infrastructure Monitoring monitored during the specified hour. |
# Custom Metrics |
The number of non-high-resolution custom metrics (MTS) that were sent to Infrastructure Monitoring during the specified hour. |
# High Res Metrics |
The number of high-resolution metrics (MTS) that were sent to Infrastructure Monitoring during the specified hour. |
Monthly usage report (multiple organizations) 🔗
If you have multiple organizations associated with your Infrastructure Monitoring subscription, an option for a summary report that includes information on multiple organizations is also available. Similar to the Monthly usage report, this report shows hourly information for hosts, containers, custom metrics, and high-resolution custom metrics. However, this report also includes this data for each organization associated with your subscription.
Hourly usage detail report 🔗
Available on the Usage Breakdown tab, the hourly usage report shows the information on MTS associated with data points sent from hosts or containers in a given hour. This report contains the MTS category keys and values, along with associated cloud provider metadata.
With this report, you can see all of the MTS categories used within a given hour period.
Note
Hourly reports are only available for host-based subscriptions.
The following table explains the different columns in an hourly usage detail report.
Column |
Description |
---|---|
Category Type |
Type of the MTS category: |
Category name |
Name of the MTS category: host or container. |
Token Id |
ID of the token associated with the category, if any. Containers or hosts with TokenId 0 are generated when detectors are created. They aren’t duplicates, and are not used in billing. |
Token Name |
Name of the token associated with the category, if any. |
Category Key |
Key of the category. For example, |
Category Value |
Value of the category. |
Cloud Provider |
Name of the cloud provider for the category. |
Cloud Region |
Cloud region associated with the category, if available. |
Availability Zone |
Availability zone associated with the category, if available. |
Project Name |
Name of the project associated with the category, if available. |
Project Number |
Number of the project associated with the category, if available. |
Subscription |
Subscription associated with the category, if available. |
Dimension report 🔗
Available on the Usage Breakdown tab, the dimension report shows the MTS information associated with data points sent from hosts or containers and information related to custom, high-resolution, and bundled MTS. It breaks down the totals by dimension so that you can trace the origination of the data.
The dimension report shows the nature of the data your organization is sending so you can adjust the data accordingly. For example, you might see some dimensions (such as environment:lab
) that indicate you are sending data for hosts or services that you don’t want to monitor using Infrastructure Monitoring.
You can select or type in a date for this report. All values in the report are based on the 24‑hour period (in UTC) for the date.
The report has 22 columns: two for dimension name and value, and four for each type of usage metric (host, container, custom, high-resolution, or bundled). If you are on a custom metrics subscription plan, you can’t see columns for host or container metrics in your report.
The following table explains the different columns in a dimension report:
Columns |
Description |
---|---|
Dimension Name and Dimension Value |
|
No. [usage metric type] MTS |
|
New [usage metric type] MTS |
|
Avg [usage metric type] MTS Resolution |
|
No. [usage metric type] Data points |
|
Older report format 🔗
The Dimension report is a revised format of the report formerly called the Metrics by Dimension report. If you select a date for the Dimension report earlier than the new format’s release, the report you download is formatted like the older Metrics by Dimension report. The old report format provides an aggregate view of the data; that is, it doesn’t show different values for different usage metrics (host, container, and so on).
Custom metric report 🔗
Available on the Usage Breakdown tab, custom metric report shows the information on MTS associated with data points sent from hosts or containers, as well as information related to custom, high-resolution, and bundled MTS, for a specified date. The content of most columns in this report represents the same kinds of values as the Dimension report, except that the information is broken down by metric name instead of by dimension name and value. Therefore, you can see how Infrastructure Monitoring is categorizing data associated with each metric.
A significant difference about this report is how you can use the No. Custom MTS column. For example, there is a non-zero value in this column. In that case, the metric is designated as a custom metric, and all MTS for this metric are counted towards the quota associated with your Infrastructure Monitoring plan. Knowing how many custom MTS your organization is sending can help you tune your usage accordingly. For example, you might notice some custom metrics that you no longer want to report to Infrastructure Monitoring. Conversely, you might decide to increase the number of custom metrics in your plan, so that you can avoid overage charges. You can use the No. High Resolution MTS column in the same way.
Manage overage charges 🔗
When you exceed your subscription limits for a sustained period of time during a monthly usage period, Splunk Observability Cloud might charge overage fees to your organization.
How we calculate monthly usage 🔗
The number of hosts, containers, and other resources that Infrastructure Monitoring monitors can fluctuate significantly over the course of a month. For this reason, Observability Cloud calculates monthly usage by using averages.
To calculate monthly usage for hosts and containers, Observability Cloud counts the number of unique hosts and containers sending metrics during each hour in the month. It then calculates the average of these counts to determine monthly usage.
To calculate monthly usage for custom and high-resolution metrics, Observability Cloud counts the number of custom and high-resolution metrics sent during each hour in the month. It then calculates the average of these counts to determine monthly usage.
Overage fees apply to each type of object individually. For example, suppose your subscription plan covers 25 hosts and 10 containers per host, or 250 containers. Let’s also suppose that you are over your limits as follows:
Hosts: 35
This is 10 hosts more than the subscription limit of 25.
Containers: 300
This is 50 containers more than the subscription limit of 250.
In this case, Observability Cloud will charge overage fees for 10 hosts and for 50 containers.
However, note that paying the overage fee for 10 hosts doesn’t automatically add 100 containers to your subscription limit and thus accommodate for the 50 additional containers. You must add 10 hosts to your subscription plan, as discussed in How to avoid overage fees, to add support for an additional 100 containers.
Create a detector to receive alerts about subscription limits 🔗
Overage fees can be as high as 110% of the monthly list price for each element for which you are over your plan’s limit. To help avoid overage fees, create a detector to proactively monitor for potential overages and receive alerts when you are nearing a subscription limit.
When creating the detector, you can use these metrics as signals on the Alert signal tab.
Item to alert on |
Metric to use as the detector signal |
---|---|
Hosts |
|
Containers |
|
Custom metrics |
|
High-resolution metrics |
|
Also, consider using one of the following conditions on the Alert condition tab:
Static Threshold condition: Set the threshold to a relatively high percentage of your limit.
Resource Running Out condition: In Alert settings, set Capacity to your limit. In Alert settings, select Show advanced settings, set the Double EWMA option to Yes.
How to avoid overage fees 🔗
If you are approaching or over your limit in any area, you have a few options available to avoid overage fees.
You can monitor fewer hosts, send in fewer custom metrics, and so forth. However, this approach of reducing your monitoring coverage is generally not the ideal solution.
Instead, Observability Cloud recommends that you correctly size your subscription, increasing your limits to match your need for hosts, containers, custom metrics, or high-resolution metrics.
If you have a Standard Edition pricing plan, you can upgrade your subscription to the Enterprise Edition, which includes support for monitoring more containers, custom metrics, and high-resolution metrics per host.
Another option is to purchase support for increasing your limits on any of these items. To get help with understanding which option is best for your organization, contact Splunk Observability Cloud support.