Hi!
Since upgrading to v.4.2 we have been having problems with going over our daily indexingvolume limits. I have tried following the guidance here to try and identify the cause, but am having p...
Hi,
I am currently testing out two searches to report and alert on the daily indexed volume.
The first search is as follows.:
index=_internal sourcetype=splunkd LicenseManager-Audit t...
It seems like our indexers do not properly get distributed load in our cluster according to our volume report alerts, it seems rather unbalanced and varies per day.
One example:
> splunk1-d...
Hi Splunkers,
I want to create an Instance overview dashboard, and one KPI should be today's estimated indexingvolume. The daily traffic varies greatly by time (significantly more over the w...
Hi ,
How to calculate indexingvolume/disk space usage for _internal index /internal DB per day In GB? Any specific query to find out top host, source type which is sending most of the logs to _...
Is there anyway to check how much log is being generated with DEBUG log mode for a particular index? Let say if index name is my_index and I need to check what is size of log generated for DEBUG m...
I have a question about managing the buckets in my volumes configured for indexes.
Below are my current configurations:
[volume:hotwarm]
path = /data/splunk/homedb
maxVolumeDataSizeMB = 9...
Hi,
Currently I have a splunk server receiving logs from few servers.
I will like to do a search that is scheduled on a daily basis which will report on the total indexed volume for all s...
Hello,
How can I determine the indexvolume by sourcetype? The reason why I ask is because occasionally I'll have a big spike in my indexvolume that threatens my license cap and I'm trying to f...