The easiest way is probably using eventcount
:
| eventcount index=myindex
http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Eventcount
Note that dbinspect
is good, but will not work in a distributed cluster, thought it can be run independently on each indexer.
The easiest way is probably using eventcount
:
| eventcount index=myindex
http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Eventcount
Note that dbinspect
is good, but will not work in a distributed cluster, thought it can be run independently on each indexer.
Depending on your specific needs, you either need metadata or dbinspect.
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/metadata
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/dbinspect