Getting Data In

how to search host volume in index



I want to search several host include in indexes. last 24hour

index name is a_1, a_2, a_3....

how to search?

thank you

Tags (1)
0 Karma


what is the result you want to achieve?

because if you want number of events per index & host it will be something like this:

index="a_*" | stats count by index,host
0 Karma


Host volume in index

0 Karma
Get Updates on the Splunk Community!

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Starting With Observability: OpenTelemetry Best Practices

Tech Talk Starting With Observability: OpenTelemetry Best Practices Tuesday, October 17, 2023   |  11AM PST / ...

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW! Every day the list of sources Admins are responsible for gets bigger and bigger, often making ...