Hi. I use a lot the metrics.log Indexer side, to debug some bottleneck and/or stress inside the Infrastructure. There is a field, i can't really understand at all, INFO Metrics - group=t...
...ndex=_internal source="\*metrics.log\*" by source
I see entries like this ...
C:\Program Files\SplunkUniversalForwarder\var\log\splunk\metrics.log
C:\Program Files\SplunkUniversalForwarder\var\l...
...ource=*metrics.log group="per_host_thruput"
| eval MB=kb/1024
| stats sum(MB)
I still get a number that's about 5.5GB less than what the licensing page is reporting.
I've tried "p...
When searching in metrics.log for the indexers in SplunkCloud I'm seeing the following: group=pipeline, name=typing, processor=regexreplacement, cpu_seconds=0.002, executes=838, cumulative_hits=1...
...iles to retain log.access_maxfiles = 5
But for the metrics.log, i only find this: [source::...\\var\\log\\splunk\\metrics.log(.\d+)?] sourcetype = splunkd
[source::...\\t...
...ifference is the number of entries in the logs.
The problem I am having is that I cannot trust on the _internal metrics.log of my indexers. Looks like it does not have all information. For example, if I r...
Splunk documentation aboutmetrics.log is nice but not entirely up to date and complete according to me.
In section "Tcpout connections messages", we are missing the aggregation parameter for t...
Hi
Hopefully someone can help. We are seeing our daily license usage being eaten up by metrics.log. Im not a Splunk expert so I don't really know what I need to do here but I know that I don't w...
Hi,
Using v4.3.3 - I’m attempting to track license usage per index. I have quite a decent discrepancy in figures the license_usage.log and metrics.log
For example, using the following I get a f...
We have a LWF on Linux that is forwarding to our indexer. We're a little tight on space, but in my experience the LWFs don't use up too much space.
On this particular LWF, the metrics.log file i...