How can I get the total number of events occurred in a particular day for all my indexes?
Like this :
index=_internal sourcetype=splunkd group=per_index_thruput | stats sum(ev) as events by series | rename series as index
Like this :
index=_internal sourcetype=splunkd group=per_index_thruput | stats sum(ev) as events by series | rename series as index