Dashboards & Visualizations

How to return the daily event count of every index?

gazoscreek
Explorer

Does anyone have a solution for a query that will return the daily event count of every index, index by index, even the ones that have ingested zero events?

| tstats count WHERE index=* OR index=_* by index ... only returns indexes that have > 0 events.

 

Labels (1)
Tags (2)
1 Solution

VatsalJagani
Champion

Run this search:

| tstats count WHERE index=* OR index=_* by index
| append [| rest /servicesNS/-/-/data/indexes count=0 | fields title | dedup title | rename title as index | eval count=0]
| stats sum(count) as count by index

 

I hope this helps!! Accept the answer if it does!!

View solution in original post

0 Karma

VatsalJagani
Champion

Run this search:

| tstats count WHERE index=* OR index=_* by index
| append [| rest /servicesNS/-/-/data/indexes count=0 | fields title | dedup title | rename title as index | eval count=0]
| stats sum(count) as count by index

 

I hope this helps!! Accept the answer if it does!!

0 Karma

gazoscreek
Explorer

Perfect solution. Thank you so much!

0 Karma
Get Updates on the Splunk Community!

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...