Splunk Search

Query to get daily amount of data in GB per index

bcastine
New Member

I am trying to figure out a search to get the amount of data in GB coming into Splunk per index. When we have huge spikes in our data, I am looking for a quick way to see which index is the culprit so I can drill down from there. Maybe something that searches all indexes and throws them into a grid.
Thank you.

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Install the Splunk On Splunk app and select Indexing->Indexing and Forwarding. That will show the top 10 indexes by volume.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Install the Splunk On Splunk app and select Indexing->Indexing and Forwarding. That will show the top 10 indexes by volume.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>