I am trying to figure out a search to get the amount of data in GB coming into Splunk per index. When we have huge spikes in our data, I am looking for a quick way to see which index is the culprit so I can drill down from there. Maybe something that searches all indexes and throws them into a grid.
Thank you.
Install the Splunk On Splunk app and select Indexing->Indexing and Forwarding. That will show the top 10 indexes by volume.
Install the Splunk On Splunk app and select Indexing->Indexing and Forwarding. That will show the top 10 indexes by volume.