<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can we find out volume of logs queried in Splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-we-find-out-volume-of-logs-queried-in-Splunk/m-p/603217#M209929</link>
    <description>&lt;P&gt;Yeah, I'm pretty sure that information is not readily available.&lt;/P&gt;&lt;P&gt;I'm still wondering what problem you're trying to solve.&amp;nbsp; If you want to reduce the data you ingest to match what users search for then knowing the volume won't help.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jun 2022 21:24:05 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-06-24T21:24:05Z</dc:date>
    <item>
      <title>How can we find out volume of logs queried in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-we-find-out-volume-of-logs-queried-in-Splunk/m-p/603194#M209919</link>
      <description>&lt;P&gt;How can we find out volume of logs queried in Splunk&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 18:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-we-find-out-volume-of-logs-queried-in-Splunk/m-p/603194#M209919</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2022-06-24T18:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find out volume of logs queried in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-we-find-out-volume-of-logs-queried-in-Splunk/m-p/603204#M209923</link>
      <description>&lt;P&gt;What volume do you seek?&amp;nbsp; Data read from disk, data returned to the SH, data returned to the user, or something else?&amp;nbsp; AFAIK, there's no good way to measure any of those aside from what's in the dispatch directory and search log (neither of which is indexed).&lt;/P&gt;&lt;P&gt;What problem are you trying to solve?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 19:01:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-we-find-out-volume-of-logs-queried-in-Splunk/m-p/603204#M209923</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-06-24T19:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find out volume of logs queried in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-we-find-out-volume-of-logs-queried-in-Splunk/m-p/603205#M209924</link>
      <description>&lt;P&gt;I am looking for&amp;nbsp;&lt;SPAN&gt;data returned to the SH and data returned to the user,I want to know that how much data is queried(not total but unique) vs how much data is not used or not queried&amp;nbsp;by any user or scheduled&amp;nbsp;search.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 19:09:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-we-find-out-volume-of-logs-queried-in-Splunk/m-p/603205#M209924</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2022-06-24T19:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: How can we find out volume of logs queried in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-we-find-out-volume-of-logs-queried-in-Splunk/m-p/603217#M209929</link>
      <description>&lt;P&gt;Yeah, I'm pretty sure that information is not readily available.&lt;/P&gt;&lt;P&gt;I'm still wondering what problem you're trying to solve.&amp;nbsp; If you want to reduce the data you ingest to match what users search for then knowing the volume won't help.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 21:24:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-we-find-out-volume-of-logs-queried-in-Splunk/m-p/603217#M209929</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-06-24T21:24:05Z</dc:date>
    </item>
  </channel>
</rss>

