Splunk Search

How to quickly count total events in an index?

muebel
SplunkTrust
SplunkTrust

Besides running "index=foo *" is there a way to quickly check the total number of events indexed in an index?

Tags (2)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

ftk
Motivator

That's way slicker than | metadata type=hosts index=foo | stats sum(totalCount)...awesome.

0 Karma

bgagliardi1
Path Finder

I found this article just now because I wanted to do something similar, but i have dozens of indexes, and wanted a sum by index over X time.

index=* | chart count(index) by index | sort - count(index) | rename count(index) as "Sum of Events"

0 Karma

earlhelms
Path Finder

6 years later, thanks!

Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...