We are using splunk for the production server. We are planning to upgrade splunk. How can we know the the time when the consumption of splunk is less(time ex: 11:00 AM or etc.,)(Suitable time to upgrade to avoid the loss of upcoming data)?
Thanks in advance
Does this do what you need ?
index=internal source=*licenseusage.log type=Usage | eval MB=b/1024/1024 | timechart span=1h sum(MB)