Ok I figured it out, this search will chart the KB per sourcetype instead of events per sourcetype but it still works to identify indexing volume changes by sourcetype:
index="_internal" source="*metrics.log" per_sourcetype_thruput | timechart sum(kb) by series
Ok I figured it out, this search will chart the KB per sourcetype instead of events per sourcetype but it still works to identify indexing volume changes by sourcetype:
index="_internal" source="*metrics.log" per_sourcetype_thruput | timechart sum(kb) by series