Getting Data In

we have daily ingestion of 7 TB but how do i know which source is sending how much data

deepthi5
Path Finder

splunk query to find how much data is coming via hec , how much data is coming via dbconnect , how much data is coming via Universal forwarder per day 

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

1st you must know what are those sources or access points what you want to calculate. Then you need to define which sources are coming through those.

Then you need to calculate totals per input types like HEC, DBX and UF.

You can use those examples from @gcusello and @PrewinThomas to get information from individual nodes, indexes etc. but you cannot get that by access type as easily.

0 Karma

PrewinThomas
Motivator

@deepthi5 

As @gcusello  mentioned, you can check on your license server. Also you can try below query,

index=_internal sourcetype=splunkd source=*license_usage.log* type=Usage
| eval GB = round(b/1024/1024/1024, 2)
| stats sum(GB) AS "Total GB" by s, st, idx
| sort - "Total GB" | rename s as Source st as Sourcetype idx as Index

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @deepthi5 ,

did you tried to use [Settings > Licensing > License Usage > Past 30 days > Splut by source] ?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...