Hello guys, Splunk newbie here.
Hope someone can assist in my case,
so index=*_whatever is expected to be filled with data in monthly basis, I want to create a dashboard that tracks whether which indexes are filled and which that are not so I can keep track and check which ones are empty and which ones are filled.
Thank you!!
Hi
There are lot of already done Apps for this issue. Here is some links for those
Slackbot 17:08
There are a lot of options for finding hosts or sources that stop submitting events:
Meta Woot! https://splunkbase.splunk.com/app/2949/
TrackMe https://splunkbase.splunk.com/app/4621/
Broken Hosts App for Splunk https://splunkbase.splunk.com/app/3247/
Alerts for Splunk Admins ("ForwarderLevel" alerts) https://splunkbase.splunk.com/app/3796/
Monitoring Console https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configureforwardermonitoring
Deployment Server https://docs.splunk.com/Documentation/DepMon/latest/DeployDepMon/Troubleshootyourdeployment#Forwarde...Some helpful posts:
https://lantern.splunk.com/hc/en-us/articles/360048503294-Hosts-logging-data-in-a-certain-timeframe
https://www.duanewaddle.com/proving-a-negative/
r. Ismo
|rest /services/data/indexes/|fields title maxTotalDataSizeMB currentDBSizeMB
|eval indexStatus = if(currentDBSizeMB>1, "Data", "Empty")
Hi @vxroot ... this can be done in multiple ways..
metadata command can be simple and less cpu/memory intensive command, than counting manually with your style of command.
let us know your how your dashboard preparation steps, you can try to include both styles and try to see which one suits you. thanks.
I'm just looking to create a simple table that has two columns first column as Index_Name and second column that should have a checkmark or a cross where checkmark = index is filled and cross = index not filled. Can replace check mark and cross with Yes / No instead too, is that possible?
index=* |stats count by index should do the trick.
Unfortunately that does not work, thanks though.
|rest /services/data/indexes/|table title maxTotalDataSizeMB currentDBSizeMB
this will show all indexes and allocated size and used size. let me know if this works for you and if you need help modifying search.