Splunk Search

Comparing raw data volume Vs indexed data volume

gnanaraj_mcc
Loves-to-Learn Lots

How do i compare my raw data volume to the indexed data volume for a specific source type?

Can someone help with this query?

We have index clustering, a deployment server, and a distributed management console.

i want to make sure their same data is not indexed more than one time. (dual, triple indexing of same data)

0 Karma

sloshburch
Ultra Champion

To determine duplicate data, you could do a | stats count by _raw, _time, host, source although I promise that will be a slow and painful process.

Indexed data volume is captured in index=_internal source=*/license_usage.log sourcetype=splunkd and then you can specify a sourcetype using the st= field.

Where do you think you have duplication? Starting with the symptoms that motivated your question will help us be more surgical in what would otherwise be a very involved process.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...