Reporting

Report on data present in index for the past 90 days - for Audit purposes

uayub
Path Finder

Hi - Can someone assist in generating a report showing that data is present in the main index for the past 90 days. This is a PCI requirement. This report should show the various months and amount of data in a chart or tabular format.

Thanks
UA

Tags (1)
0 Karma

lguinn2
Legend

This should work

index=main | bucket _time span=1mon | stats count as EventCount by _time source host
0 Karma

lguinn2
Legend

Thanks @martin_mueller, I edited my answer to include _time

I hadn't thought of using tstats like that

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

180x speedup for a 50GB SplunkIT index on my PC:

alt text
alt text

tstats ran first, so any cache warming effects were in favour of stats 🙂

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Shouldn't the stats also be grouped by _time to show the various months?

Also, this should do the same and be orders of magnitude faster:

| tstats count as EventCount where index=main by _time source host span=1mon

lguinn2
Legend

Sorry, my bad

0 Karma

uayub
Path Finder

It says the argument host in invalid and does not execute.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...