Installation

How to calculate data ingestion from a specific Heavy Forwarder

pm2012
Explorer

Hi SMEs,

Hope you are doing great, i am curious to know how to check the daily data consumption (GB/Day) from a specific Heavy Forwarder using Splunk search when there are multiple HFs are there in the deployment. thanks in advance

Labels (1)
Tags (1)
0 Karma

pm2012
Explorer

Thanks for the valueable query, few points here

1- I am unable to locate my HF under h field (search from IP as well as hostname)

2- How can i put restriction on day basis, like to create bar chart having license consumption during the week

3- I have another way to look into it as i mainly would like to calculate data ingestion where index name having common starting name like index="test*" and i found a field which is idx to query the same. However how to add all the data and show it in graph

4- Also i think this is license in GB , | eval licenseGB =round(license/1024/1024/1024,3). Why did you rename it to TB?

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @pm2012 

you can use following query

index=_internal source="*license_usage.log" type=Usage h="<forwader name>"

| rename _time as Date

| eval Date=strftime(Date,"%b-%y")

| stats sum(b) as license by Date h

| eval licenseGB =round(license/1024/1024/1024,3)

| rename licenseGB as TB



0 Karma

andygerberkp
Explorer

Don't you mean

| rename licenseGB as GB



0 Karma
Get Updates on the Splunk Community!

Buttercup Games Tutorial Extension - part 9

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games Tutorial Extension - part 8

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Introducing the Splunk Developer Program!

Hey Splunk community! We are excited to announce that Splunk is launching the Splunk Developer Program in ...