Getting Data In

Data Indexed in a specifc interval

leapop
Engager

What will be the query to find out the bytes indexed by a server during a specific interval - absolute time period?

Thanks.

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

You would have to do:

earliest=1/2/2011:12:34:56 latest=2/2/2011:1:23:45 index=_internal source=*metrics.log group=per_index_thruput | timechart sum(kb) by series
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...