Hello friends!
Today there are very strange behavior on splunk server.
On the average Volume used today = 50-120MB
But today i has some crazy numbers = 2,936 MB, but number of events in the database about the same from day to day.
Prompt how can I trace with any of forwarders is so much traffic?
Thank you!
You could check the metrics logs.
index=_internal source=*metrics.log group=per_host_thruput | eval MB=kb/1024 | stats sum(MB) by series
You could check the metrics logs.
index=_internal source=*metrics.log group=per_host_thruput | eval MB=kb/1024 | stats sum(MB) by series