I was wondering if anyone had a link to some web page that lists the sizes (in bytes) for various common IT data event source types, like Cisco ASA, Microsoft IIS, Bluecoat, WebSphere/WebLogic log4j or logback, insert_your_common_sourcetype_here, etc.
Please see this Splunk Wiki table for more details, or to add your own events and their sizes now:
Any idea how you would find the TOTAL size of events by sourcetype in an index?
Thanks! This will help a lot!
Here's the same search but also showing the 10th and 90th percentile for event size (in bytes) broken down by sourcetype :
If you want to check the average size in bytes of your events broken down by sourcetype, you can run the search below. Of course, feel free to replace "*" with a specific data set you want to study, and don't forget to adequately set the time frame of the search :
Isn't it simply the length of the _raw field? e.g. the value given by esize is only the number of characters.