Hi, I have multiple hosts and would like to find out the approximate daily Log size of each host . Please help me to resolve my issue
Hi @sunny2013
Can you try this,
index=_internal Metrics group=per_host_thruput sourcetype=splunkd
| timechart span=1d sum(kb) as KB by series
| eval MB=KB/1024
| rename series as host----
An upvote would be appreciated and Accept solution if this reply helps!