Splunk Dev

How do I build a report with total events For SMS?

noviceinsplunk
New Member

At the end of the day, is it feasible to tally the number of successful events to compare with yesterday’s total without too much performance overhead?

It seems this would run for a long time.

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi,

  • Is it feasible to tally number of successful events, at the end of day, to compare with yesterday’s total; without performance overhead?

Answer: Yes, it's not a performance overhead at all, depending on your logs/event volume.

Please provide us the search query for today's logs.. check the volume for one day..
if the size is huge, then you can choose summary indexing..

overall, it "appears" to be a feasible task.

and, SMS meaning?

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

noviceinsplunk
New Member

Text or PUSH message too.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...