Splunk Dev

Search for the volume of data ingested into a specific index in MB

rleadingham
Engager

I have spent hours today researching and testing all sort of searches and I just cannot figure out how to find the information I want. I would have thought it would have been straight forward to find the total volume of data sent to a specific index in MB.

I have came close but only by experimenting with many examples I found on the site.

Any advice would be very much appreciated.

Thank you!

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Try this (gives the amount of license used for indexes)

index=_internal sourcetype=splunkd source=*license_usage.log type=Usage 
| stats sum(b) as bytes by idx | eval mb=round(bytes/1024/1024,3)

View solution in original post

woodcock
Esteemed Legend
0 Karma

somesoni2
Revered Legend

Try this (gives the amount of license used for indexes)

index=_internal sourcetype=splunkd source=*license_usage.log type=Usage 
| stats sum(b) as bytes by idx | eval mb=round(bytes/1024/1024,3)

splunkdevabhi
Explorer

How to check the daily indexing in such cases ? Would adding span=1d and a timechart help?

0 Karma

somesoni2
Revered Legend

If you want overall, then you can use this timechart version

index=_internal sourcetype=splunkd source=*license_usage.log type=Usage 
 | timechart span=1d sum(b) as usage_mb| eval usage_mb=round(usage_mb/1024/1024,3)

For per index, you can use this

  index=_internal sourcetype=splunkd source=*license_usage.log type=Usage 
     | timechart span=1d sum(b) as usage by idx limit=0 | foreach * [ eval "<<FIELD>>"=round('<<FIELD>>'/1024/1024,3)]

OR

 index=_internal sourcetype=splunkd source=*license_usage.log type=Usage 
     | bucket span=1d _time | stats sum(b) as bytes by _time idx | eval mb=round(bytes/1024/1024,3)
0 Karma

rleadingham
Engager

This is absolutely perfect thank you very much. I have what I am looking for and I have learnt more about how to query in Splunk!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...