Splunk Enterprise

Calculate total consumed cold storage for all indexers

jcspigler2010
Path Finder

I have found ways to calculate total storage for all indexers per index. But how would I focus in on what is only occupying coldPath space? Possibly break this down per index.

thanks!

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

you can use the | dbinspect command
cold buckets are under state = cold.
then you can create searches calculating the total size by using sizeOnDiskMB field
so something like that:
| dbinspect index=* state = cold | eval indexSizeGB = sizeOnDiskMB / 1024 | stats sum(indexSizeGB) by index

Hope it helps

View solution in original post

adonio
Ultra Champion

you can use the | dbinspect command
cold buckets are under state = cold.
then you can create searches calculating the total size by using sizeOnDiskMB field
so something like that:
| dbinspect index=* state = cold | eval indexSizeGB = sizeOnDiskMB / 1024 | stats sum(indexSizeGB) by index

Hope it helps

jcspigler2010
Path Finder

Thanks adonio

Had to expand on this a little hit. You can't filter on the state until the search is ran. I did the following

| dbinspect index=* | eval indexSizeGB = sizeOnDiskMB / 1024 | stats sum(indexSizeGB) as "Total Size in GBs" by index,state | search state=cold

Thanks pointing me in the right direction!

0 Karma

adonio
Ultra Champion

You are welcome!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...