I have used the following query to find indexer host wise mb consumed in indexeing.
index=internal source=*metrics.log group=perindex_thruput series="Myindex" | eval MB=kb/1024 | stats sum(MB) by host | addcoltotals
but in this list i could see my forwarders hosts are also being displayed...and the Myindex is having almost double size of the data... can you pls help ?? wat needs to be checked to solve this problem ?
Are your forwarders set to index AND forward, or forward only?
Alternatively, is there some mechanism whereby you could be capturing the same information twice, or forwarding it to multiple indexers? And what version Splunk are you running? Older versions will see the same data directed at multiple indexers as separately accountable.