Probably a few ways of doing this, but if you have access to index=_internal you can try something like this. index=_internal component=Metrics group=per_index_thruput earliest=-30d@d latest=now
...
See more...
Probably a few ways of doing this, but if you have access to index=_internal you can try something like this. index=_internal component=Metrics group=per_index_thruput earliest=-30d@d latest=now
| bucket span=1h _time
| stats
sum(kb) as hourly_kb,
sum(ev) as hourly_events,
by _time, series
| stats
earliest(_time) as earliest_event,
latest(_time) as latest_event,
count as sample_size,
avg(hourly_kb) as avg_hourly_kb,
sum(hourly_kb) as total_kb,
avg(hourly_events) as avg_hourly_events,
sum(hourly_events) as total_events
by series
| convert
ctime(earliest_event),
ctime(latest_event)
| rename
series as index