Splunk Search

How can we find out volume of logs queried in Splunk?

kml_uvce
Builder

How can we find out volume of logs queried in Splunk

kamal singh bisht
Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What volume do you seek?  Data read from disk, data returned to the SH, data returned to the user, or something else?  AFAIK, there's no good way to measure any of those aside from what's in the dispatch directory and search log (neither of which is indexed).

What problem are you trying to solve?

---
If this reply helps you, Karma would be appreciated.
0 Karma

kml_uvce
Builder

I am looking for data returned to the SH and data returned to the user,I want to know that how much data is queried(not total but unique) vs how much data is not used or not queried by any user or scheduled search.

kamal singh bisht
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yeah, I'm pretty sure that information is not readily available.

I'm still wondering what problem you're trying to solve.  If you want to reduce the data you ingest to match what users search for then knowing the volume won't help.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...