Splunk Enterprise

I need to get the average daily GB usage per index over 30 days

nls7010
Path Finder

I have been trying to put together a dashboard for my clients that shows their usage.  The search I am still having issues with is for Average Daily ingest by index over 30 days.  I want it to show just the average number.  I have found searches that get me a distance, but none are specifically what I need.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
What is your current search?
---
If this reply helps you, Karma would be appreciated.
0 Karma

nls7010
Path Finder

This is the search:

index=_internal source=*license_usage.log* type="Usage" earliest=-30d@d latest=@d idx=apcne
| fields _time, pool, idx, b
| eval idx=if(len(idx)=0 OR isnull(idx),"(UNKNOWN)",idx)
| bin _time span=24h
| stats sum(b) as b by _time, pool, idx
| stats sum(b) AS volume by idx, _time
| stats avg(volume) AS avgVolume max(volume) AS maxVolume by idx | eval avgVolumeGB=round(avgVolume/1024/1024/1024,2)
| eval maxVolumeGB=round(maxVolume/1024/1024/1024,2)
| fields idx, avgVolumeGB, maxVolumeGB
| rename avgVolumeGB AS "average" maxVolumeGB AS "peak" idx AS "Index"

0 Karma
Get Updates on the Splunk Community!

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...