Deployment Architecture

Raw logs/data size info sent to indexer - consolidated info from all indexers

etell
New Member

Is there a way to find out how much data is being sent to the indexer(s) or the size of raw data that has already been indexed?
One can login to the indexer and follow Manager->Indexes and get the index size “Current size (MB)”. However,a consolidated way of getting this info from the search-head would be helpful; instead of visiting each indexer. Is there such mechanism in palce?

0 Karma
1 Solution

RicoSuave
Builder

Yes. Using Rest via the search language to hit the indexer endpoint. the following search will do the trick

| rest /services/data/indexes | chart sum(currentDBSizeMB) by splunk_server

Selected timeframe will not have an effect.

View solution in original post

RicoSuave
Builder

Yes. Using Rest via the search language to hit the indexer endpoint. the following search will do the trick

| rest /services/data/indexes | chart sum(currentDBSizeMB) by splunk_server

Selected timeframe will not have an effect.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...