Hi splunkers,
Good day! I just to ask if possible to see the per indexvolume usage? Let's just say I have multiple indexes like index1 index2 index3. Then I want to create a dashboard that will c...
...n the Indexer Clusters:Master Node dashboard but can only see internal and default indexes in the test environment. Using ./splunk cmd btool indexes list --debug on an indexer in each environment I c...
Hi!
Since upgrading to v.4.2 we have been having problems with going over our daily indexingvolume limits. I have tried following the guidance here to try and identify the cause, but am having p...
Is there anyway to check how much log is being generated with DEBUG log mode for a particular index? Let say if index name is my_index and I need to check what is size of log generated for DEBUG m...
Hi,
I am currently testing out two searches to report and alert on the daily indexed volume.
The first search is as follows.:
index=_internal sourcetype=splunkd LicenseManager-Audit t...
It seems like our indexers do not properly get distributed load in our cluster according to our volume report alerts, it seems rather unbalanced and varies per day.
One example:
> splunk1-d...
I have a question about managing the buckets in my volumes configured for indexes.
Below are my current configurations:
[volume:hotwarm]
path = /data/splunk/homedb
maxVolumeDataSizeMB = 9...
I'm using the free version, I just started using it. I created a dashboardand had data from another box being sent to splunk via UDP and the dashboard I created with the 3 charts is gone.
I had i...
Hi Splunkers,
I want to create an Instance overview dashboard, and one KPI should be today's estimated indexingvolume. The daily traffic varies greatly by time (significantly more over the w...