Getting Data In

Data Indexed in a specifc interval

leapop
Engager

What will be the query to find out the bytes indexed by a server during a specific interval - absolute time period?

Thanks.

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

You would have to do:

earliest=1/2/2011:12:34:56 latest=2/2/2011:1:23:45 index=_internal source=*metrics.log group=per_index_thruput | timechart sum(kb) by series
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...