<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how much data does a particular sourcetype ingest daily in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139706#M28717</link>
    <description>&lt;P&gt;Hi Martin, i do have access to _internal.&lt;BR /&gt;
thanks but that only gives me top 10 sourcetypes, what if i want sourcetype A and B and C, which exist in lets say 3 different indexes X, Y , Z.&lt;BR /&gt;
bascially i want to get the size of the windows security/system/event logs on a daily basis. These are all being captured as different sourcetypes from a few different indexes.&lt;/P&gt;</description>
    <pubDate>Sun, 13 Jul 2014 20:25:16 GMT</pubDate>
    <dc:creator>gurinderbhatti</dc:creator>
    <dc:date>2014-07-13T20:25:16Z</dc:date>
    <item>
      <title>how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139702#M28713</link>
      <description>&lt;P&gt;i am trying to modify the below search&lt;/P&gt;

&lt;P&gt;index=&lt;EM&gt;internal metrics kb series!=&lt;/EM&gt;* "group=per_host_thruput" daysago=5 | eval indexed_mb = kb / 1024 | timechart fixedrange=t span=1d sum(indexed_mb) by series | rename sum(indexed_mb) as totalmb&lt;/P&gt;

&lt;P&gt;this gives me top sourcetypes and how much data they consume daily.&lt;/P&gt;

&lt;P&gt;but what if i have a particular indexes (index=gold and index=silver) and a particular sourcetype or sourcetypes (security, windows,etc)&lt;/P&gt;

&lt;P&gt;how do i figure out how much data these particular sourcetypes from both these indexes are ingesting daily? and if i wanted these numbers over 7 days but also wanted the mix/max/avg as well. can someone write up a quick query? thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:02:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139702#M28713</guid>
      <dc:creator>gurinderbhatti</dc:creator>
      <dc:date>2020-09-28T17:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139703#M28714</link>
      <description>&lt;P&gt;Grab the SoS app from &lt;A href="http://apps.splunk.com/app/748/"&gt;http://apps.splunk.com/app/748/&lt;/A&gt; - that should quench most of your indexing volume reporting thirst.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2014 16:14:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139703#M28714</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-11T16:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139704#M28715</link>
      <description>&lt;P&gt;thanks Martin, &lt;BR /&gt;
im trying to find where to exactly get this info. seems to me the charts are broken on my sos app. &lt;BR /&gt;
anyway i can integrate that logic into the search above?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2014 18:11:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139704#M28715</guid>
      <dc:creator>gurinderbhatti</dc:creator>
      <dc:date>2014-07-11T18:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139705#M28716</link>
      <description>&lt;P&gt;Do you have permission to read the &lt;CODE&gt;_internal&lt;/CODE&gt; index? If you do then it'd be interesting to find out why your SoS charts are broken.&lt;/P&gt;

&lt;P&gt;As for getting that manually, you can see throughput per sourcetype using this query taken from SoS:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source="*metrics.log" group=per_sourcetype_thruput | timechart minspan=30s per_second(kb) by series
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 12 Jul 2014 07:52:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139705#M28716</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-12T07:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139706#M28717</link>
      <description>&lt;P&gt;Hi Martin, i do have access to _internal.&lt;BR /&gt;
thanks but that only gives me top 10 sourcetypes, what if i want sourcetype A and B and C, which exist in lets say 3 different indexes X, Y , Z.&lt;BR /&gt;
bascially i want to get the size of the windows security/system/event logs on a daily basis. These are all being captured as different sourcetypes from a few different indexes.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jul 2014 20:25:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139706#M28717</guid>
      <dc:creator>gurinderbhatti</dc:creator>
      <dc:date>2014-07-13T20:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139707#M28718</link>
      <description>&lt;P&gt;Add &lt;CODE&gt;limit=0&lt;/CODE&gt; to the &lt;CODE&gt;timechart&lt;/CODE&gt; to see more than ten sourcetypes, or add &lt;CODE&gt;series=A OR series=B OR series=C&lt;/CODE&gt; to the base search to just see your three interesting sourcetypes.&lt;/P&gt;

&lt;P&gt;The indexes used don't matter, this shows throughput per sourcetype over all indexes.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jul 2014 20:54:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139707#M28718</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-13T20:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139708#M28719</link>
      <description>&lt;P&gt;The SOS app has a nice view on this. You can find it in the SOS app -&amp;gt; indexing -&amp;gt; index performance. Make sure you set the view to "sourcetype". If you don't want to go through the trouble of installing the SOS app (however it's really useful), here's the search that gives the same results:&lt;/P&gt;

&lt;P&gt;source="*metrics.log" group=per_sourcetype_thruput | timechart minspan=30s  per_second(kb) by series useother=false limit=15&lt;/P&gt;

&lt;P&gt;Above search shows all sourcetype over all indexes&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:03:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139708#M28719</guid>
      <dc:creator>renems</dc:creator>
      <dc:date>2020-09-28T17:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139709#M28720</link>
      <description>&lt;P&gt;Hi Martin, thank you very much. im almost there!&lt;BR /&gt;
so the series=A/B/C query works. Only issue is we have over 20+ windows indexes and they all collect data for these specific sourcetypes series=WinEventLog:System/Security/Application&lt;BR /&gt;
However, i only want this data from index=1, index=2, index=4&lt;BR /&gt;
index=_internal source="*metrics.log" index=1 group=per_sourcetype_thruput series=WinEventLog:System OR series=WinEventLog:Security OR series=WinEventLog:Application| timechart limit=0 minspan=1h per_hour(kb) by series&lt;BR /&gt;
doesnt seem to work&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:03:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139709#M28720</guid>
      <dc:creator>gurinderbhatti</dc:creator>
      <dc:date>2020-09-28T17:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139710#M28721</link>
      <description>&lt;P&gt;I see... I don't think the regular metrics logging lets you split by both index and sourcetype, only one or the other. You could try and compute that like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index=1 OR index=2 OR index=3) (sourcetype=A OR sourcetype=B OR sourcetype=C) | eval length = length(_raw) | stats sum(length) as byte by sourcetype index | eval mb = byte / 1048576
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That'll run for a while though.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2014 20:11:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139710#M28721</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-14T20:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139711#M28722</link>
      <description>&lt;P&gt;i was told not to use the metrics.log because it is not accurate and truncates data after top 20 hosts.i think adding the limit function should resolve that. &lt;BR /&gt;
using license_usage gives 2 colums for each WinEventLog type(diff vals) y?.Also how do i tell it what indexes to query? seems like it takes all the indexes into account. &lt;BR /&gt;
thanks in advance....&lt;BR /&gt;
index=_internal source=*license_usage.log type=usage st="WinEventLog:Security"OR st="WinEventLog:Application"OR st="WinEventLog:System" |eval GB = b/1024/1024/1024| rename st AS sourcetype |timechart span=1d sum(GB) AS "Total GB used" by sourcetype&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:04:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139711#M28722</guid>
      <dc:creator>gurinderbhatti</dc:creator>
      <dc:date>2020-09-28T17:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: how much data does a particular sourcetype ingest daily</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139712#M28723</link>
      <description>&lt;P&gt;Ah yes, the &lt;CODE&gt;license_usage.log&lt;/CODE&gt; events may do what you need. Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*license_usage.log type=usage (st="WinEventLog:Security" OR st="WinEventLog:Application" OR st="WinEventLog:System") (idx=index1 OR idx=index2 OR idx=index3) | eval GB = b/1024/1024/1024 | eval st_idx = st.": ".idx | timechart span=1d sum(GB) as "Total GB used" by st_idx
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 14 Jul 2014 21:21:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-much-data-does-a-particular-sourcetype-ingest-daily/m-p/139712#M28723</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-14T21:21:32Z</dc:date>
    </item>
  </channel>
</rss>

