Hello,
Can anyone tell me where I would go to find daily log storage info? I am trying to get an average of how much storage per day is currently being used, so I can figure out what license I would need to purchase.
Any info is much appreciated!
Jesse Jorgensen
This search will show you the amount of data for your indexes for 1 day.
index=_internal source=*license_usage.log | eval GB=b/1024/1024/1024 | timechart span=1d sum(GB) by st useother=0
Also in the UI you can go to the Search App -> Status (menu) -> Index Activity -> Indexing Volume. The Splunk on Splunk App also provides all of the details in addition to the health of your environment.
http://
The search above got me started in the right direction. I find this outputs the data in a more elegant format:
index=_internal source=*license_usage.log
earliest=-24h
| eval GB=round(b/1024/1024/1024, 2)
| stats sum(GB) count by st
| sort - sum(GB)
This search will show you the amount of data for your indexes for 1 day.
index=_internal source=*license_usage.log | eval GB=b/1024/1024/1024 | timechart span=1d sum(GB) by st useother=0
Also in the UI you can go to the Search App -> Status (menu) -> Index Activity -> Indexing Volume. The Splunk on Splunk App also provides all of the details in addition to the health of your environment.
http://
That's just what I needed. Thanks for your help!