Building for the Splunk Platform

How do I build a report with total events For SMS?

noviceinsplunk
New Member

At the end of the day, is it feasible to tally the number of successful events to compare with yesterday’s total without too much performance overhead?

It seems this would run for a long time.

Tags (1)
0 Karma

inventsekar
Super Champion

Hi,

  • Is it feasible to tally number of successful events, at the end of day, to compare with yesterday’s total; without performance overhead?

Answer: Yes, it's not a performance overhead at all, depending on your logs/event volume.

Please provide us the search query for today's logs.. check the volume for one day..
if the size is huge, then you can choose summary indexing..

overall, it "appears" to be a feasible task.

and, SMS meaning?

0 Karma

noviceinsplunk
New Member

Text or PUSH message too.

0 Karma
Get Updates on the Splunk Community!

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...