Getting Data In

forwarder and indexing volume

templier
Communicator

Hello friends!

Today there are very strange behavior on splunk server.

On the average Volume used today = 50-120MB
But today i has some crazy numbers = 2,936 MB, but number of events in the database about the same from day to day.

Prompt how can I trace with any of forwarders is so much traffic?

Thank you!

0 Karma
1 Solution

Ayn
Legend

You could check the metrics logs.

index=_internal source=*metrics.log group=per_host_thruput | eval MB=kb/1024 | stats sum(MB) by series

View solution in original post

Ayn
Legend

You could check the metrics logs.

index=_internal source=*metrics.log group=per_host_thruput | eval MB=kb/1024 | stats sum(MB) by series
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...