Splunk Search

Can you use tstats to get daily index or indexer volume?

Glasses
Builder

Just wondering if its possible to get data volume / size from TSTATS.

I know you can do something like this to get counts (events/per sec)

| tstats count WHERE index=* by index| eval events_per_second=count/(3600*24)

but how can you use tstats for find volume of data per time?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

As far as I can tell, there is no indexed field that indicates data volume so you can't use tstats to get that value.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

As far as I can tell, there is no indexed field that indicates data volume so you can't use tstats to get that value.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Glasses
Builder

thank you for confirming, I could not find a list of tstats fields.... is there a doc for tstat fields?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is no documentation for tstats fields because the list of fields is not fixed. It depends on which fields you choose to extract at index time. You can, however, use the walklex command to find such a list.

walklex type=term index=foo 
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...