Getting Data In
Highlighted

How can I check event size?

Path Finder

Hi,

Is there any way to determine which events takes a lot of storage/data? It will help me to bypass those events if required.

0 Karma
Highlighted

Re: How can I check event size?

Splunk Employee
Splunk Employee

Hey @chintan_shah, did I edit your question correctly? Are you hoping to check your licensing limits? Or is this for your own storage capacity?

0 Karma
Highlighted

Re: How can I check event size?

Splunk Employee
Splunk Employee

Hey chintan_shah!

Check out the meta woot! app on splunkbase.

It provides many must have views for Splunk Admins, including a licensing data model that show you license usage per event:

alt text

This will allow you to monitor how much license a sourcetype/index are using per event.

Once you narrow it down you can then use a search like this to investigate the raw events

index=internal sourcetype="splunkd"
| eval eventSize=len(
raw)
| table eventSize _raw
| sort - eventSize

and append | stats max(eventSize), avg(eventSize), min(eventSize) to keep some high level stats on your data.

alt text

0 Karma
Highlighted

Re: How can I check event size?

Contributor

@mmodestino_splunk

I am trying to check the license usage consumption by event pattern and trying to create a report which would say which event patterns are consuming more license.

0 Karma