We want to take a look at our bucket sizes to see if they are rolling too quickly due to thier size. I assume in the _internal index there is some jucy tidbits of into about buckets. Any help is MUCH apprecaiated.
For seeing the current size of buckets I use dbinspect
The default maxDataSize is 750mb if not specifically set in indexes.conf.
Warm buckets might be a bit larger due to post processing and buckets might be smaller if data is sparse or Splunk is restarted before the hot buckets fill to 750mb.