Splunk Enterprise Security

Percentage of Indexes’ logs in 24 hours.

SabariRajanT
Path Finder

Can someone help me to identify Percentage of Indexes’ logs in 24 hours.?

I have pulled using count like this :index=* earliest=-24h@h latest=now | stats count by index

But need this in Percentage.

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
index=* earliest=-24h@h latest=now 
| stats count by index
| eventstats sum(count) as total
| eval percent=round((count * 100) / total, 2)
| fields - total

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
index=* earliest=-24h@h latest=now 
| stats count by index
| eventstats sum(count) as total
| eval percent=round((count * 100) / total, 2)
| fields - total
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...