Hi all.
What search command do I have to use to get the file size in bytes if there is no field called bytes?
Can anyone help me with this?
Thank you very much
If you are monitoring a file, something like this might work:
<YOUR BASE SEARCH>
| eval bytes=length(_raw)
| stats sum(bytes) by source
Since an ASCII character is 1 byte, and _raw represents an event, you can calculate per event, then sum by source, which should be representative of the log file the data came from. This is dependent upon the assumption that the entire file has been ingested.
What sourcetype are you talking about?
Do you have any size field? If so, use eval
to convert the value in that field to bytes.