Getting Data In
Highlighted

How much data is ingested by a single sourcetype from defined host/clientname

Path Finder

How much data in MB/GB is ingested by a single sourcetype from defined host/clientname

0 Karma
Highlighted

Re: How much data is ingested by a single sourcetype from defined host/clientname

SplunkTrust
SplunkTrust

Try this

index=_internal sourcetype=splunkd source=*license_usage.log type=Usage h=YourHostNameHere st=YourSourceTypeHere
| stats sum(b) as usage by h st | eval usageMB=roung(usage/1024/1024,3)
0 Karma
Highlighted

Re: How much data is ingested by a single sourcetype from defined host/clientname

Path Finder

Not getting serverlist in prod...

0 Karma
Highlighted

Re: How much data is ingested by a single sourcetype from defined host/clientname

Splunk Employee
Splunk Employee

Do want to mention a typo in the provided SPL.

It should be:

 index=_internal sourcetype=splunkd source=*license_usage.log type=Usage h=YourHostNameHere st=YourSourceTypeHere
 | stats sum(b) as usage by h st | eval usageMB=round(usage/1024/1024,3)
0 Karma