We would like to track our Splunk Enterprise Cluster performance to keep an eye on whether we have sufficient resources allocated, as part of this we would like to track average search queue volume and wait time but I have had a hard time finding any way to generate this data.
Is this data exposed anywhere for searching in Splunk? we are using the MC saturated event queue for the indexers already as well as CPU / Mem usage for both indexers and search heads.