Hi.. yes... Best would be to use the S.o.S Splunk app. It should provide what you need and more. You can also search internal index(depending on your environment/search head configuration). Eg: Something like index=_internal earliest=-30m per_index_thruput will give you info on the data received from various hosts in the past 30 min from indexers responding to your search head... check out the available Fields and tweak the search per your requirement. You do this on Web or Use CLI /REST.