Hi guys, My boss check on Splunk Master and see that, he want to know index, source, sourcetype, capacity of log/day for each sourcetype, How can I see that I used this search before, but I fe...
See more...
Hi guys, My boss check on Splunk Master and see that, he want to know index, source, sourcetype, capacity of log/day for each sourcetype, How can I see that I used this search before, but I feel its not corect 100%, | dbinspect index=*
| stats sum(rawSize) as total_size by index
| eval total_size_mb = total_size / (1024 * 1024)
| table index total_size_mb How I can check this on my Indexer, I can ssh to Indexer too. Thank you for your time