Splunk Cloud Platform

total amount of data logged per host or source or sourcetype

Sid
Explorer

Hi Team,

I have containerized sc4s hosts which have ufs installed  but sc4s is forwarding data via HEC, i want to see the total logging size per host or sc4s source, can someone help me with the query to get that data .

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check the searches from the license report and adjust to your needs.

0 Karma

Sid
Explorer

@PickleRick  we have cloud deployment and i see only two panels in ingest , i want data by per sc4s host not splunk server. 

Sid_0-1722445468339.png

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. Cloud can be different here. My way works in an on-prem environment.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...