Getting Data In

How can I check event size?

Path Finder


Is there any way to determine which events takes a lot of storage/data? It will help me to bypass those events if required.

0 Karma

Splunk Employee
Splunk Employee

Hey chintan_shah!

Check out the meta woot! app on splunkbase.

It provides many must have views for Splunk Admins, including a licensing data model that show you license usage per event:

alt text

This will allow you to monitor how much license a sourcetype/index are using per event.

Once you narrow it down you can then use a search like this to investigate the raw events

index=_internal sourcetype="splunkd"
| eval eventSize=len(_raw)
| table eventSize _raw
| sort - eventSize

and append | stats max(eventSize), avg(eventSize), min(eventSize) to keep some high level stats on your data.

alt text

- MattyMo
0 Karma



I am trying to check the license usage consumption by event pattern and trying to create a report which would say which event patterns are consuming more license.

0 Karma

Splunk Employee
Splunk Employee

Hey @chintan_shah, did I edit your question correctly? Are you hoping to check your licensing limits? Or is this for your own storage capacity?

0 Karma
Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...