Splunk Search

Query to get daily amount of data in GB per index

New Member

I am trying to figure out a search to get the amount of data in GB coming into Splunk per index. When we have huge spikes in our data, I am looking for a quick way to see which index is the culprit so I can drill down from there. Maybe something that searches all indexes and throws them into a grid.
Thank you.

0 Karma
1 Solution

SplunkTrust
SplunkTrust

Install the Splunk On Splunk app and select Indexing->Indexing and Forwarding. That will show the top 10 indexes by volume.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

Install the Splunk On Splunk app and select Indexing->Indexing and Forwarding. That will show the top 10 indexes by volume.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma