The Atlas Data Utilization Element provides Splunk owners with comprehensive insights about the utilization of the data in your environment. Use Data Utilization to identify utilization trends, discover which data sources are getting the most or least amount of usage by your Splunk users, and understand how utilization correlates to your daily data ingest. Data Utilization allows for a rapid assessment of what business value a specific Splunk is providing because you can see who is using and how it is being used.
The information provided by the Data Utilization Element is crucial for supporting optimization efforts, implementing data hygiene best practices in your Splunk environment, and helping to ensure you're getting optimal from your data. The goal of Data Utilization is to support critical decision making for when you may need to stop ingesting data that is no longer being used to save on system resources or to discover data that is being underutilized and could be used to support new valuable use cases. These are just some of the use cases supported by Atlas Data Utilization.
Data Utilization Capabilities
Analyzes Index and Source Type utilization across ad-hoc searches, scheduled searches, and dashboards
Provides key metrics that identify underutilized datasets along with the volume of splunk license it represents
Provides a comprehensive list of all datasets by index:sourcetype or index:sourcetype:source and their specific utilization stats
Provides query counts, license usage, and queries/GB distribution metrics by dataset in multiple formats
Identifies which users, searches, and dashboards are utilizing data along with which installed Splunk app is impacted
Quickly view the SPL being run against data
Easily identify inefficient searches being run by your Splunk users
Provides a comprehensive view of data utilization across your Splunk environment in a single view