Splunk Search
Highlighted

Log Volume Indexed.

Communicator

I would like to display the volume indexed from several indexed into following chart.

  • Past 24hrs log volume by time (line graph)
  • Past week’s log volume (bar chart – bar for each day)

It should be Per Host combined since would be filtering the hosts by tags.

Tags (2)
0 Karma
Highlighted

Re: Log Volume Indexed.

Splunk Employee
Splunk Employee

earliest=-24h index=_internal source=*metrics.log group=per_host_thruput | rename series as host | tags | where tag=mytag | timechart span=1h sum(kb) by host

earliest=-7d@d latest=@d index=_internal source=*metrics.log group=per_host_thruput | rename series as host | tags| where tag=mytag | timechart span=1d sum(kb) by host
Highlighted

Re: Log Volume Indexed.

Communicator

"index=internal source=*metrics.log group=perhostthruput | rename series as host | tags | search tag::host=mytag" this seems to work However when I check this I get very less hosts compared to "
| metadata type=hosts | TAGS | search tag::host=mytag | eval host=lower(host) | fields host| rename host as "series" | join
series[search index="
internal" source="*metrics.log" perhostthruput | stats sum(kb) by series] "

0 Karma
Highlighted

Re: Log Volume Indexed.

Communicator

"index=internal metrics group=perhostthruput startdaysago=7 | rename series as host | tags | search tag::host=MyTags | bucket span=1d _time | stats sum(kb) as kb by datemday" . This works for me.Is there any fine tuning to be done?

0 Karma