Splunk Search

Splunk query to get top sorcetypename=kubernetes_logs, devided by services (or namespaces)

alekseisaiko
Path Finder

Hi there!
I need a query, that will show me Top Sourcetype Sizes by Day, where sourcetype=kubernetes_logs, and the kubernetes_logs itself, to divide by service names (or namespace names).
RIght now, I'm using this query -

index=_internal source=*license_usage.log type="Usage"
| eval indexname = if(len(idx)=0 OR isnull(idx),"(UNKNOWN)",idx)
| eval sourcetypename = st
| bin _time span=1d
| stats sum(b) as b by _time, pool, indexname, sourcetypename
| eval GB=round(b/1024/1024/1024, 3)
| fields _time, indexname, sourcetypename, GB
| sort by GB
| reverse

But how do I exclude only kubernetes_logs from here, and divide it by service names?

Thanks!

0 Karma
1 Solution

alekseisaiko
Path Finder
0 Karma

alekseisaiko
Path Finder

Solved it

0 Karma

alekseisaiko
Path Finder

Or maybe source must be used instead of sourcetypename? For example “kube:container"? But still I have no success to pull the container logs

0 Karma

to4kawa
Ultra Champion

sample of results please.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...