Thanks Giuseppe This is what I got going for myself in test mode my event indexes have _e_ in them, metrics have _m_ in them and summary has .. earliest=-11m@m latest=-1m@m index=*_e_* OR index=*_m_* NOT index=*summary*
| eval logsize=len(_raw)
| stats sum(logsize) as log_bytes count as log_count by host sourcetype
| eval log_count.{host}.{sourcetype} = log_count
| eval log_bytes.{host}.{sourcetype} = log_bytes
| fields - log_count log_bytes host sourcetype
| stats values(*) as *
| addinfo | mcollect index=log_volume_stats_summary_test split=allnums
... View more