We are using Splunk Cloud and the Cloud Monitoring Console provides a graph showing the KB/s and Events/s per forwarding instance and I would like to manipulate this query to provide the total average per day across a number of different forwarders, does anyone know what the search being used is?