<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring Splunk Users Search Disk Usage in Security</title>
    <link>https://community.splunk.com/t5/Security/Monitoring-Splunk-Users-Search-Disk-Usage/m-p/36326#M1212</link>
    <description>&lt;P&gt;A quick way to determine a user's quota is to run the following search on the search head:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;| rest splunk_server=local /services/search/jobs | eval diskUsageMB=diskUsage/1024/1024 | stats sum(diskUsageMB) by eai:acl.owner&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;

&lt;P&gt;d.&lt;/P&gt;</description>
    <pubDate>Sat, 25 Aug 2012 19:06:48 GMT</pubDate>
    <dc:creator>_d_</dc:creator>
    <dc:date>2012-08-25T19:06:48Z</dc:date>
    <item>
      <title>Monitoring Splunk Users Search Disk Usage</title>
      <link>https://community.splunk.com/t5/Security/Monitoring-Splunk-Users-Search-Disk-Usage/m-p/36325#M1211</link>
      <description>&lt;P&gt;I would like to understand the profile our users have for their searches in order to determine the optimal value to place the default search disk quota at.  Where would that type of information be logged in the internal tables?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2012 21:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitoring-Splunk-Users-Search-Disk-Usage/m-p/36325#M1211</guid>
      <dc:creator>sanderso67</dc:creator>
      <dc:date>2012-08-15T21:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Splunk Users Search Disk Usage</title>
      <link>https://community.splunk.com/t5/Security/Monitoring-Splunk-Users-Search-Disk-Usage/m-p/36326#M1212</link>
      <description>&lt;P&gt;A quick way to determine a user's quota is to run the following search on the search head:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;| rest splunk_server=local /services/search/jobs | eval diskUsageMB=diskUsage/1024/1024 | stats sum(diskUsageMB) by eai:acl.owner&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;

&lt;P&gt;d.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Aug 2012 19:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitoring-Splunk-Users-Search-Disk-Usage/m-p/36326#M1212</guid>
      <dc:creator>_d_</dc:creator>
      <dc:date>2012-08-25T19:06:48Z</dc:date>
    </item>
  </channel>
</rss>

