Splunk Search

How to quickly count total events in an index?

muebel
SplunkTrust
SplunkTrust

Besides running "index=foo *" is there a way to quickly check the total number of events indexed in an index?

Tags (2)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

ftk
Motivator

That's way slicker than | metadata type=hosts index=foo | stats sum(totalCount)...awesome.

0 Karma

bgagliardi1
Path Finder

I found this article just now because I wanted to do something similar, but i have dozens of indexes, and wanted a sum by index over X time.

index=* | chart count(index) by index | sort - count(index) | rename count(index) as "Sum of Events"

0 Karma

earlhelms
Path Finder

6 years later, thanks!

Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...