Getting Data In

Is there a way to determine how much disk space my sourcetype is taking up?

a212830
Champion

Hi,

Is there a way to determine how much disk space a sourcetype is using?

Tags (2)
1 Solution

jlanders
Path Finder

So here's one option. You can see how much data you are indexing for a given time period per sourcetype. The general rule for Splunk disk storage is 1/2 X Indexing X Days. Example: 1/2 X 5 gb X 365 days = 912.5 GB of storage.

index=internal metrics kb series!=* "group=per_sourcetype_thruput" | stats sum(indexed_mb) by series

Another option might be using the dbinspect command:

| dbinspect index=my_index

If you can estimate the percentage of the index your sourcetype takes up, you can can an accurate estimate of the disk usage. Reference: http://docs.splunk.com/Documentation/Splunk/6.1.4/SearchReference/Dbinspect

View solution in original post

jlanders
Path Finder

So here's one option. You can see how much data you are indexing for a given time period per sourcetype. The general rule for Splunk disk storage is 1/2 X Indexing X Days. Example: 1/2 X 5 gb X 365 days = 912.5 GB of storage.

index=internal metrics kb series!=* "group=per_sourcetype_thruput" | stats sum(indexed_mb) by series

Another option might be using the dbinspect command:

| dbinspect index=my_index

If you can estimate the percentage of the index your sourcetype takes up, you can can an accurate estimate of the disk usage. Reference: http://docs.splunk.com/Documentation/Splunk/6.1.4/SearchReference/Dbinspect

awurster
Contributor

in 6.1 that didn't seem to work at all for me. i found success with the following:

index=_internal metrics kb group=per_sourcetype_thruput | eval sizeMB = round(kb/1024,2)| stats sum(sizeMB) by series | sort -sum(sizeMB) | rename sum(sizeMB) AS "Size on Disk (MB)"

chadmedeiros
Path Finder

I would be careful to convert to MB and round after sum'ing, not before

0 Karma

TomSquare31
Engager

Utilized your method @awurster and it worked perfectly. Thanks

Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...