Getting Data In

Data calculate from heavy forwarders and intermediate forwarders to indexer cluster

Mani2
Explorer

Hi,

I wanted to check that how can I get total data transfer from on-prem heavy forwarders and intermediate forwarders to cloud indexer cluster? is there a search which can look into splunkd.log or metrics.log from heavy forwarder for data transferred for 24 hours...

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps this will help

index=_internal host=<<forwarder name>> component=Metrics name=thruput earliest=-24h
| stats sum(total_k_processed) as "total data transfer"
---
If this reply helps you, Karma would be appreciated.

Mani2
Explorer

Thanks Rich, that helps.
How can I get it in MB or GB as it is tough to read "91345084304594.000"

0 Karma

Mani2
Explorer

Sorry missed to ask,

And how can I see same in this search result for multiple hosts ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Easy-peasy

index=_internal host=* component=Metrics name=thruput earliest=-24h
| stats sum(total_k_processed) as "total data transfer" by host
```Convert KB to GB```
| eval "total data transfer" = 'total data transfer'/1024/1024
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...