Anyone have a search that will return the indexed events per second across the entire indexer cluster?
Here's a modification of an MC search. I changed 'kb' to 'ev' to get events instead of volume.
`dmc_set_index_internal` host=RGALLOWAY source="*metrics.log" sourcetype=splunkd group=per_Sourcetype_thruput
| eval ingest_pipe = if(isnotnull(ingest_pipe), ingest_pipe, "none")
| search ingest_pipe=*
| `dmc_timechart_for_metrics_log` per_second(ev) useother=false limit=15
Here's what I've got so far. Anyone got something better?
index=_internal sourcetype=splunkd source="/opt/splunk/var/log/splunk/metrics.log" group=per_host_thruput aws_role=splunk_indexer | stats avg(eps) as eps by host | eval _time=now() | stats sum(eps) as total_eps