Hi everyone,
Now I'm working splunk site to site. I have splunk indexer at HQ and splunk forwarder at branch.
I'm testing send data from branch to splunk indexer at HQ.
How can I search for total time splunk indexing data from branch per source="xxxx.log" and bandwidth speed of data transfer between site.
Thanks you for advise.
All events have a field called _indextime
which is the time the event was indexed. You can start with a search like this:
... | eval lagSeconds=_indextime - _time | eval bytes=length(_raw)
Now for each event, you have the number of bytes transferred (bytes) and the latency (lagSeconds). You can take it from there.
All events have a field called _indextime
which is the time the event was indexed. You can start with a search like this:
... | eval lagSeconds=_indextime - _time | eval bytes=length(_raw)
Now for each event, you have the number of bytes transferred (bytes) and the latency (lagSeconds). You can take it from there.