VOL — Volume Outliers¶
Volume Outliers tracks the licensed volume of every Splunk index — the volume you pay for — and answers a question the other components leave open: is my license volume normal? Each entity is one index; its state comes from ML outlier detection on the rolling volume (abnormal drops and / or spikes) and from inactivity (an index that silently stops consuming license). On top of the detection, VOL records the daily licensed volume per license day, a 30-day trend and a month projection, per index and for the whole environment.
Where DSM watches feeds arrive on time, VOL watches how much arrives, from one source that is authoritative, cheap to read and identical on every Splunk deployment: the license usage log. One tenant covers a whole Splunk deployment — local or remote, Splunk Enterprise or Splunk Cloud — in a few clicks, with the history backfilled automatically so detection and the cost trend are usable on day one.
What VOL tracks¶
Signal |
What it means |
|---|---|
Volume outliers |
Each index has its own ML model on its rolling 24-hour licensed volume (the shorter windows — 60 min, 4 h, 12 h — can be modelled too). A value outside the learned range is a drop (lower bound) or a spike (upper bound). The detection direction — drops, spikes, or both — is chosen per index; the tenant sets the default. Outliers are the state of the component, not an option. |
Inactivity |
An index whose last licensed volume is older than the threshold in force turns red. The threshold is a tenant policy — static, or variable by day of week and hour of day (by default 1 day during working hours, 7 days for nights and week-ends) — and can be overridden per index. |
Daily licensed volume |
The volume of each license day (the day rolls at the license manager’s local midnight, whatever your search head’s time zone), the figure your license is measured on. Reported per index and summed for the environment. |
Trend and projection |
A 30-day trend, the month-to-date volume and a month projection that follows the weekday pattern of the index — recomputed every 5 minutes, per index and for the whole environment. |
Pool usage |
On Splunk Enterprise, the share of the license pool consumed over the last 24 hours; the entity’s group is its license pool. On Splunk Cloud a pool has no limit, so no pool usage is reported. |
Every index is a regular TrackMe entity: priority, tags, labels, SLA, logical groups, the disruption queue, acknowledgments, notes, maintenance, stateful alerting and the AI Assistant all apply. VOL has no thresholds to configure and no delay / latency — there is nothing to tune before it delivers value.
How it collects¶
One tracker per tenant runs every 5 minutes and reads only the new events of the license
usage log — one bounded search, whatever the number of indexes — into 5-minute buckets
per index. The rolling KPIs, the daily volumes and the projection are derived from those
buckets, never by rescanning _internal. The tracker writes the trackme.splk.vol.*
metrics with explicit bucket timestamps, so the charts and the ML models see a continuous,
regular series.
At creation the tenant backfills its history (30 days by default, up to 90, bounded by the retention of the license usage log): the same collection replayed over the past, hour by hour, so the outliers models train immediately and the daily history is complete from the first day. Progress is visible on the tenant card, in the Tenant Home header and in the Manage: volume collection screen. See Backfill for the details.
Global license usage¶
Next to the VOL component tab, Tenant Home offers a read-only Global license usage (VOL) tab — the dashboard people otherwise build by hand: key figures (licensed yesterday, daily average, peak day, trend, month to date, month projection, concentration), insights in plain words, the stacked daily volume of the top consumers, the whole environment per day with its projection and the daily quota line on Splunk Enterprise, the consumers table, the week-over-week movers and the pool cards. It reads what the tenant already collected, so it adds no search on the license usage log and works the same on a remote deployment.
Creating a VOL tenant¶
Create a tracking tenant and pick the Splunk Volume (Outliers) card.
Basics — the tenant identifier, alias and description.
Volume — the target environment (this Splunk, or a remote account), the default detection direction, the backfill history, which priorities are in scope for outliers, the minimum history a model needs before its confidence is normal, and the default outliers KPIs. Advanced holds the license search constraint and the settle margin.
Inactivity — the tenant’s inactivity policy (static, or variable by day and hour).
Indexes & RBAC — the TrackMe indexes, the roles and the owner, as for every tenant.
Review and create. The first collection runs at once; the backfill follows on its own schedule.
The wizard is walked step by step in Creating a splk-vol tenant, and end to end — from creation to the first alert — in the Volume Outliers white paper.
Tip
Foundation customers get it too. VOL is part of the Foundation edition, next to DSM, DHM and MHM — a Foundation deployment can monitor its license volume out of the box, without Flex Objects. Enterprise and Unlimited include it as well.
Note
Replaces the Flex Objects license-usage recipes. Before 2.4.18, volume outliers on the
license usage were delivered with Flex Objects templates
(splk_license_usage_per_index_*) and, per feed, with the DSM volume models. VOL packages
that recipe as a first-class component: cheaper to run, backfilled, with a purpose-built UI.
The templates remain available for custom needs.
See also
Volume Outliers — in depth — the collector, license days and time zones, the backfill, outliers and inactivity policies, the projection, the Global license usage tab, alerting, REST and metrics.
Volume outliers on the Splunk license usage — the white paper: an end-to-end walkthrough on a live deployment.
Machine Learning — how outlier detection works.
Entity State & Scoring — states and scoring.