Thank you both for the feedback. I am not sure what the value in the search represents. Is that the amount of events, size in GB, etc.? The search below works. Given the numerous fields I just want to find the amount of data in these various fields so we can see where most of our data is sitting. Seeing the amount of data in an index and sourcetype are great but we need to dig deeper within the data to see where most of the data is logging. index=index_name | eval raw_len=(len(_raw)/1024/1024/1024) | stats sum(raw_len) as GB by field_name | sort -GB
... View more