Getting Data In

How to determine index volume by sourcetype?

echojacques
Builder

Hello,

How can I determine the index volume by sourcetype? The reason why I ask is because occasionally I'll have a big spike in my index volume that threatens my license cap and I'm trying to find the best way to determine the cause of the spike. If I can create a chart that shows volume by sourcetype (over X hours) then I can identify the culprit and dig in from there.

Or even better, is there a search that I can run that actually identifies the cause of the spike (not just the sourectype)?

Thanks!

1 Solution

ykherianDEPRECA
Splunk Employee
Splunk Employee

Trust the license usage (not the metrics) form the license-master.

Example for the size for yesterday

earliest=-1d@d latest=@d  index=_internal source=*license_usage.log* type=Usage 
| stats sum(b) AS Bytes by st 
| sort -Bytes

see more here : http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

View solution in original post

ykherianDEPRECA
Splunk Employee
Splunk Employee

Trust the license usage (not the metrics) form the license-master.

Example for the size for yesterday

earliest=-1d@d latest=@d  index=_internal source=*license_usage.log* type=Usage 
| stats sum(b) AS Bytes by st 
| sort -Bytes

see more here : http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

echojacques
Builder
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...