Monitoring Splunk

Search to return cluster ingest rate (KB/s)

nnesje
Loves-to-Learn Lots

I'm looking for a search I can run that will return the ingest rate (KB/s) across the entire cluster.  I know there's a "Deployment-Wide Total Indexing Rate" panel in the DMC dashboard "Indexing Performance: Deployment" that contains this data but I need to recreate this on the cluster itself to push to a summary index for retention and quick export. 

Also, if there's a similar search that will return events/s, I'm looking for that as well.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

When you click on the magnifying glass icon in the lower-right corner of a MC dashboard panel the panel will open in a Search window where you can modify the query as desired and then save it in your dashboard or report.

---
If this reply helps you, Karma would be appreciated.
0 Karma

nnesje
Loves-to-Learn Lots

Understood, but saving those dashboard panels as a separate report in the DMC doesn't help me. I need to re-create those searches NOT in the DMC, which is a stand-alone searchhead and not part of the shcluster. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Once you have the search open you can copy it anywhere you need it.  It doesn't have to stay on the MC.  You will, however, need to expand the DMC macros used by the search.

---
If this reply helps you, Karma would be appreciated.
0 Karma

nnesje
Loves-to-Learn Lots

Can you go into more detail on "expanding the macros" for the DMC-based searches?  As I understand it, the DMC is running jobs that collect data from the cluster and store it on the DMC, then the dashboards call that data via the searches/macros.  When I try to copy/run a search that's part of a dashboard in the DMC on a non-DMC searchhead that's part of the cluster, I'm not seeing anything since the DMC data is not searchable from the SH cluster.  I'm happy to hear if I'm wrong or if there's another way to access DMC data from the main cluster.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...