Reporting

How do I get a complete size of all logs ingested by Splunk Enterprise & Enterprise Security incl. Indexes

SamHTexas
Builder

How do I get a complete size of all logs ingested by Splunk Enterprise & Enterprise Security incl. Indexes. Showing indexes taking the most load?

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console can show which indexes are getting the most data.  It will even break it out by source, sourcetype, and (IIRC) host.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

Thank u again Rich. Does the sizes show are the complete ( including all logs) for the Indexes. Are there any other place I need to check to come up with complete metrics? I am doing this for sake of saving licenses going over the limit. Would you by any chance have " best practices" for trimming the license fat ? Thank u sir.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The first Best Practice is to only ingest what you need.  Disable inputs for use cases you're not monitoring.  Increase the input interval where possible.  Be picky about which Windows events you ingest.

Trim the fat from Windows events.  They all contain the same boiler-plate text at the end that serves no useful purpose.  See https://docs.splunk.com/Documentation/SplunkCloud/8.1.2101/Data/MonitorWindowseventlogdata#Suppress_... and https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-truncation-at-IDX-and-HF/m-p...

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...