Splunk Search

totalCount in |metadata command: current number of events or lifetime count of events?

Jason
Motivator

Is the number of events reported as totalCount in | metadata...

  • the lifetime running total of the events for that (source|sourcetype|host), so the number only goes up

... or ...

  • the current total, so the number could go up and down once buckets start rolling out of indexes?
Tags (1)

rshoward
Path Finder

UPDATE: It is a total indexed over lifetime counter. I ran the trend on a huge data set that has a full index that is cycling out old events. For the last week the totalCount for all assets have only been increasing. The numbers also differ in the billions from the index stats when added up.

----original----

My initial test shows it is the "current total" you speak of; meaning it could go up and down. I'm running another test now with a larger set of data then I'll let you know once I ingest more from another host which should reduce the value of totalCount when the limit is hit. (I have a trend running on that value per host so it should dip once I complete these bulk tests)

0 Karma

rshoward
Path Finder

Jason, sorry for the delay. I let the trend run for a week just to be sure. I've update the answer with my findings.

0 Karma

Jason
Motivator

Thanks. Do you have a result from that larger data set?

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...