Getting Data In

disk usage for indexer

a212830
Champion

Hi,

Is there a way to track disk usage per day for indexes?

Tags (2)
0 Karma

barakreeves
Splunk Employee
Splunk Employee

On Windows, Mark Russinovich who brought us sysinternals, has a 'du' utility. This needs to be downloaded...or: run the "diskuse" command
On UNIX, run:
du -h -s

Run both as a scripted output.

You can have this command set to run every few hours or minutes and of course, Splunk the data. Once the data is in, you can create alerts.

0 Karma

a212830
Champion

setup for both internal and non-internal indexes.

0 Karma

barakreeves
Splunk Employee
Splunk Employee

How about going to Manager » Access controls » Roles » admin Indexes at the bottom and make sure Internal indexes are available; I have run into this before so it is the first thing I typically check. Let me know.

0 Karma

a212830
Champion

Returns nothing.

0 Karma

barakreeves
Splunk Employee
Splunk Employee

Try running this query: index=_internal type="Usage"
This query Splunks data from the license_usage.log file; one of the fields returned is "Pool" among other fields

0 Karma

a212830
Champion

Thought so. Thanks. So, now that I know that, how can I get license usage for the past week for a specific license pool?

0 Karma

Ayn
Legend

No, because indexes are compressed whereas license usage concerns the uncompressed amount of data.

0 Karma

a212830
Champion

So, a question on this - does license usage translate to disk storage use?

0 Karma

treinke
Builder

Are you looking to say these files were modified, added, deleted? Or are you looking to say the hard drive has this much free space and alert me when it is at this level? What is the OS that you want all this on?

There are no answer without questions
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...