Monitoring Splunk

Measuring count of searches using Cold Buckets

dsctm3
Path Finder

Hello,

I am trying to collect key data metrics regarding search volumes accessing the varying tiers of Splunk Storage Buckets.

For example, I would love to see a report that says

xx% of searches are accessing warm buckets only
xx% of searches are accessing both warm and cold buckets

So far the only hope I've seen thus far is watching Disk IO volume for the cold mounts to get a idea of "how busy it is", and I am hoping for better information from Splunk Itself.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...