Splunk Search

totalCount in |metadata command: current number of events or lifetime count of events?

Jason
Motivator

Is the number of events reported as totalCount in | metadata...

  • the lifetime running total of the events for that (source|sourcetype|host), so the number only goes up

... or ...

  • the current total, so the number could go up and down once buckets start rolling out of indexes?
Tags (1)

rshoward
Path Finder

UPDATE: It is a total indexed over lifetime counter. I ran the trend on a huge data set that has a full index that is cycling out old events. For the last week the totalCount for all assets have only been increasing. The numbers also differ in the billions from the index stats when added up.

----original----

My initial test shows it is the "current total" you speak of; meaning it could go up and down. I'm running another test now with a larger set of data then I'll let you know once I ingest more from another host which should reduce the value of totalCount when the limit is hit. (I have a trend running on that value per host so it should dip once I complete these bulk tests)

0 Karma

rshoward
Path Finder

Jason, sorry for the delay. I let the trend run for a week just to be sure. I've update the answer with my findings.

0 Karma

Jason
Motivator

Thanks. Do you have a result from that larger data set?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...