Reporting

Report on data present in index for the past 90 days - for Audit purposes

uayub
Path Finder

Hi - Can someone assist in generating a report showing that data is present in the main index for the past 90 days. This is a PCI requirement. This report should show the various months and amount of data in a chart or tabular format.

Thanks
UA

Tags (1)
0 Karma

lguinn2
Legend

This should work

index=main | bucket _time span=1mon | stats count as EventCount by _time source host
0 Karma

lguinn2
Legend

Thanks @martin_mueller, I edited my answer to include _time

I hadn't thought of using tstats like that

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

180x speedup for a 50GB SplunkIT index on my PC:

alt text
alt text

tstats ran first, so any cache warming effects were in favour of stats 🙂

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Shouldn't the stats also be grouped by _time to show the various months?

Also, this should do the same and be orders of magnitude faster:

| tstats count as EventCount where index=main by _time source host span=1mon

lguinn2
Legend

Sorry, my bad

0 Karma

uayub
Path Finder

It says the argument host in invalid and does not execute.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...