Hi, I've been trying to piece together a query that a power user could run that could report the GB/Day of data indexed for a particular index without having to access the license usage data (which a power user wouldn't have access to).
I've been trying to leverage the dashboards in the Monitoring app but nothing seems to be quite what I need. I'd like to get the deployment wide GB/day indexed for a single index which seems easy but so far I haven't been able to crack it.
Any suggestions?
In any case, power user won't have access to the _internal index. You can either calculate the usage based on individual index like " | eval event_size=if(isnotnull(len(_raw)), len(_raw), 0) | stats sum(event_size) as total_bytes by sourcetype | eval total_gb=round(total_bytes/1024/1024/1024, 3)"
OR
Create a saved search through the admin user which updates the lookup (or summary index) with ingestion details and let power users access that lookup / summary index for Dashboard panels.
The last option would be easy to manage and suggested.
Please accept the answer if that helps!
Let me check that out and I will mark it gratefully. 😀
In any case, power user won't have access to the _internal index. You can either calculate the usage based on individual index like " | eval event_size=if(isnotnull(len(_raw)), len(_raw), 0) | stats sum(event_size) as total_bytes by sourcetype | eval total_gb=round(total_bytes/1024/1024/1024, 3)"
OR
Create a saved search through the admin user which updates the lookup (or summary index) with ingestion details and let power users access that lookup / summary index for Dashboard panels.
The last option would be easy to manage and suggested.
Please accept the answer if that helps!