Hello all,
I just came onto a new job and we're trying to figure out the daily indexing rate broken down by sourcetypes. Then we're going to get the average for X days. Is there another search that can list the throughput of each sourcetype within an index? I like the search below for per_sourcetype_thruput, but it doesn't list the indexes. I tried looking at the per_index_thruput to figure it out too but am now stuck trying to see if there are other commands out there that can help.
index=_internal component=Metrics per_sourcetype_thruput
| eval mb=kb/1024
| timechart span=1d sum(mb) by series useother=f limit=150
index=_internal component=Metrics per_index_thruput
| eval mb=(kb/1024)
| timechart span=1d sum(mb) by series useother=f limit=100
Thank you for your time, take care.
try this? This gives volume usage stats for the index and sourcetype on daily basis
index=_internal source="*license_usage.log*" type=Usage | eval yearmonthday=strftime(_time, "%Y%m%d") | stats sum(eval(b/1024/1024)) AS volume_mb by idx st yearmonthday
try this? This gives volume usage stats for the index and sourcetype on daily basis
index=_internal source="*license_usage.log*" type=Usage | eval yearmonthday=strftime(_time, "%Y%m%d") | stats sum(eval(b/1024/1024)) AS volume_mb by idx st yearmonthday
Thank you nareshinsvu! It worked perfectly.