Monitoring Splunk

How to identify network traffic sent from indexers and from search head to user?

diegosainz
Path Finder

Is there a way in splunk to identify how much network traffic is being sent from the indexers (not just how much is indexed)? In addition, can I find a rough estimate of traffic from search head to user? I am not sure if Splunk logs this, but I was hoping.

Tags (2)

somesoni2
Revered Legend

There is a Splunk SOS app (http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk) which provide so many statistical data about splunk instance, and I believe Network volume is one the metrics it reports on. Worth checking out.

Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...