How to identify network traffic sent from indexers and from search head to user?

Path Finder

Is there a way in splunk to identify how much network traffic is being sent from the indexers (not just how much is indexed)? In addition, can I find a rough estimate of traffic from search head to user? I am not sure if Splunk logs this, but I was hoping.

Tags (2)


There is a Splunk SOS app ( which provide so many statistical data about splunk instance, and I believe Network volume is one the metrics it reports on. Worth checking out.

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!