Splunk Enterprise

Usage for specific Host

Bisho-Fouad
Explorer

Hey there , kindly need support how to determine received logs SIZE for specific Host. Prefers to be done through GUI 

Hit: working on distributed environment also own License master instance 

 

thanks in advance, 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Bisho-Fouad .. on the DMC / license master.. you can find out the license usage of a specific host. 

pls suggest us exactly which step/status you are in.. 

 

As you are asking GUI.. the SPL gives more control actually. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

yeahnah
Motivator

Hi @Bisho-Fouad 

Here's an example search to solve your question...

 

host=<your host> ``` and whatever else you need to filter your data ````
| eval bytes = length(_raw)  ``` generally 1 character = 1 byte ```
| stats sum(bytes) AS bytes BY source   ``` this gives the size of each log, assuming the source is the name of the log file ```
| eval kilobytes = bytes/1024)
| evenstats sum(kilobytes) AS total_kb

 

Hope that helps

 

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...