Reporting

Report on data present in index for the past 90 days - for Audit purposes

uayub
Path Finder

Hi - Can someone assist in generating a report showing that data is present in the main index for the past 90 days. This is a PCI requirement. This report should show the various months and amount of data in a chart or tabular format.

Thanks
UA

Tags (1)
0 Karma

lguinn2
Legend

This should work

index=main | bucket _time span=1mon | stats count as EventCount by _time source host
0 Karma

lguinn2
Legend

Thanks @martin_mueller, I edited my answer to include _time

I hadn't thought of using tstats like that

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

180x speedup for a 50GB SplunkIT index on my PC:

alt text
alt text

tstats ran first, so any cache warming effects were in favour of stats 🙂

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Shouldn't the stats also be grouped by _time to show the various months?

Also, this should do the same and be orders of magnitude faster:

| tstats count as EventCount where index=main by _time source host span=1mon

lguinn2
Legend

Sorry, my bad

0 Karma

uayub
Path Finder

It says the argument host in invalid and does not execute.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...