I tried to interpret the output the REST endpoint from Splunk doc:
and have problem understanding the 2 output parameters totalrawsize and total_size
totalrawsize (If totalsize > 0) Cumulative size (fractional MB) on disk of the
Why is totalrawsize bigger the total_size? Note that I got the same result when applying this API on my cluster.
rawSize: The volume in bytes of the raw data files in each bucket. This value represents the volume before compression and the addition of index files.
sizeOnDisk: The size in MB of disk space that the bucket takes up expressed as a floating point number. This value represents the volume of the compressed raw data files and the index files.
totalrawsize: essentially uncompressed bytes indexed on this indexer for this index
total_size: essentially size on disk for after compression and indexing metadata on this indexer for this index
On average it will be normal for totalsize to be 50% of totalraw_size.