Monitoring Splunk

Determining Log Rates/Sizes

SLS-CCU
New Member

Our networking team is looking to determine Log Rates for different systems reporting in Splunk.

How can we determine how often a log is created for an individual system and determine the average size of these logs?

Thank you!

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

It depends on what mechanism you use to collect the data and wheyher you can reliably distinguish between different sources. If - for example you have several hosts reporting to a common syslog input which sets source as udp:514 and they are misconfigured and don't report their hostname correctly (or simply log in some strange format that doesn't produce reasonable host field), there is no way to calculate stats per single source, you can just have aggregated values. But that's also a design problem on a completely different level because having an event you can't tell where it came from.

So the answer to your question is highly dependent on your particular architecture and configuration.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SLS-CCU,

if you're speaking of logs from other servers with Splunk Universal Forwarder, using the Splunk Monitoring Console app you can see the the rate of logs flows from each server.

Instead if you want to measure logs from appliances using syslog, you have to see in the License consuption dashboard and you can have the values of the logs daily ingested for each appliance, so you can meke an average.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...