Hi,
I would like to get the following stats in a distributed index setup:
index name, current size of index (sum all indexers), maximum size/quota allocated, first events timestamp, last events timestamp, total retention time
Thanks
Shanker
Try this
| rest /services/data/indexes | table title splunk_server currentDBSizeMB frozenTimePeriodInSecs maxTime minTime totalEventCount
Details of returned values can be found here.
http://docs.splunk.com/Documentation/Splunk/6.0.2/RESTAPI/RESTindex
Try this
| rest /services/data/indexes | table title splunk_server currentDBSizeMB frozenTimePeriodInSecs maxTime minTime totalEventCount
Details of returned values can be found here.
http://docs.splunk.com/Documentation/Splunk/6.0.2/RESTAPI/RESTindex
From the result the minTime values seems inaccurate. My splunk setup is only 1 month old but the minTime is giving timestamps from year 2011, 2012 etc. Any idea why?
Thanks
Shanker
Thanks 🙂 Gives me exactly what I wanted.