Splunk Search

ソースタイプ別データ取り込み量確認方法

Splunk_Shinobi
Splunk Employee
Splunk Employee

ソースタイプ別に取り込まれているデータの容量を1日毎や1時間毎などで表示したいのですが、
SplunkのSearch画面から可能ですか?

Tags (1)
0 Karma
1 Solution

melonman
Motivator

以下の様な感じではいかがでしょうか。

index=_internal sourcetype="splunkd" group="per_sourcetype_thruput" series!=splunk* | eval gb=kb/1024/1024 | timechart limit=20 minspan=1d sum(gb) by series

View solution in original post

melonman
Motivator

以下の様な感じではいかがでしょうか。

index=_internal sourcetype="splunkd" group="per_sourcetype_thruput" series!=splunk* | eval gb=kb/1024/1024 | timechart limit=20 minspan=1d sum(gb) by series
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...