Installation

Too many indexed bytes reported

rschutt
Explorer

I'm running the following search:

index="_internal" source="*license_usage.log"

The problem is that all hosts report received bytes, eventhough there are no events received. The lowest number I have seen is 134 bytes (b=134). Does anyone know why I see these and how I can report on the real number of indexed bytes? Thanks!

0 Karma

rschutt
Explorer

The strange thing is that I tested the same on another deployment and on this I won't get any of these entries in license_usage.log if no events occur, which is what I expected. On the initial deployment I see every minute a new event in license_usage.log with "h" being my forwarder and "b" always showing at least 134 bytes, eventhough I cannot find any events from this forwarder. So where are these bytes going? I should see them in any of the non-internal indexes, right?

0 Karma

yannK
Splunk Employee
Splunk Employee

you need to group per source sourcetype host indexer, (s/h/st/i) to have useful numbers.
You can check the examples of searches on license_usage there :
http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

0 Karma

joshd
Builder

I've listed some searches on my blog to show the license breakdown by source, sourcetype, host, per index statistics and so on... I would start with running these various searches to narrow down where the actual culprit is...

http://www.joshd.ca/content/splunk-usage-statistic-searches

I would also suggest downloading and using the Splunk Deployment Monitor app as it can provide a wealth of information:

http://splunk-base.splunk.com/apps/22301/splunk-deployment-monitor

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...