Hi,
I have pushed a data from a file into Splunk.
The size of the file is 94921b but when I pushed into Splunk, the size of the index from _internal is 90965b.
The index I have used to push the data is a brand new index created.
This is how I compared between the size of file and size of index in Splunk
File: 'log_100kb.log' Size: 94921 Blocks: 200 IO Block: 32768 regular file |
Results from the _internal index 07-11-2023 01:51:44.679 -0700 INFO LicenseUsage - type=Usage s="http:100kb_logs" idx="100kb_logs" b=90965 ....... |
May I know why is the size different between the file and the index, please?
Thank you.