Getting Data In
Highlighted

Re: Index volume by host

Explorer

I found it!!!

Thank you very much.

/opt/splunk/bin/splunk search "index=internal source=*licenseusage.log type=Usage earliest=-1d@d latest=-0d@d | eval MB=b/1024/1034 | stats sum(MB) by h | sort sum(MB) | reverse" -auth test:test123

View solution in original post

0 Karma
Highlighted

Re: Index volume by host

Splunk Employee
Splunk Employee
0 Karma