Reporting

Report on data present in index for the past 90 days - for Audit purposes

uayub
Path Finder

Hi - Can someone assist in generating a report showing that data is present in the main index for the past 90 days. This is a PCI requirement. This report should show the various months and amount of data in a chart or tabular format.

Thanks
UA

Tags (1)
0 Karma

lguinn2
Legend

This should work

index=main | bucket _time span=1mon | stats count as EventCount by _time source host
0 Karma

lguinn2
Legend

Thanks @martin_mueller, I edited my answer to include _time

I hadn't thought of using tstats like that

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

180x speedup for a 50GB SplunkIT index on my PC:

alt text
alt text

tstats ran first, so any cache warming effects were in favour of stats 🙂

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Shouldn't the stats also be grouped by _time to show the various months?

Also, this should do the same and be orders of magnitude faster:

| tstats count as EventCount where index=main by _time source host span=1mon

lguinn2
Legend

Sorry, my bad

0 Karma

uayub
Path Finder

It says the argument host in invalid and does not execute.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...