Splunk Search

How to quickly count total events in an index?


Besides running "index=foo *" is there a way to quickly check the total number of events indexed in an index?

Tags (2)
1 Solution

Splunk Employee
Splunk Employee


That's way slicker than | metadata type=hosts index=foo | stats sum(totalCount)...awesome.

0 Karma

Path Finder

I found this article just now because I wanted to do something similar, but i have dozens of indexes, and wanted a sum by index over X time.

index=* | chart count(index) by index | sort - count(index) | rename count(index) as "Sum of Events"

0 Karma

Path Finder

6 years later, thanks!

Get Updates on the Splunk Community!

What’s new on Splunk Lantern in August

This month’s Splunk Lantern update gives you the low-down on all of the articles we’ve published over the past ...

Welcome to the Future of Data Search & Exploration

You have more data coming at you than ever before. Over the next five years, the total amount of digital data ...

This Week's Community Digest - Splunk Community Happenings [8.3.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...