Getting Data In

How would i calucate the no of days that the data is present in my indexes ??

rakesh_498115
Motivator

Hi..

I have certain indexes say "myperf" and "myapp" of 60 GB Size . Now in these indexes i need to calucalte how many days of data is present . i.e in that 60 GB size how many days of data can i see in my index before moving the data from hot to cold.

I have tried this ..

index=myperf | stats earliest(_indextime) as earliest latest(_indextime) as latest | eval duration = latest - earliest | eval Days = (duration/(24*60))

this seems to be not working..

tried one more like this

index=myperf | eval Day=strftime(_time,"%d-%b-%y") | stats dc(Day)

this is taking so much time . Is there any way i can get the Days count pls ??

Tags (2)
0 Karma

rakesh_498115
Motivator

Hi

Found the ans with the following query ..

| metadata index=myperf type=hosts | stats max(lastTime) as lastTime, min(firstTime) as firstTime | eval duration = lastTime - firstTime | eval Days = (duration/(24*60*60))

🙂

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...