Getting Data In

How to monitor and report the amount of data indexed per host?

feickertmd
Communicator

How can I use Splunk to tell me how much data per day each host is forwarding to Splunk? Basically, I need a report that shows the host name and how much data it passed through the Splunk forwarder in bytes.

Tags (3)
0 Karma
1 Solution

somesoni2
SplunkTrust
SplunkTrust

This might help

index=_internal sourcetype=splunkd group=per_host_thruput | timechart sum(kb) as totalkb by series limit=0

View solution in original post

somesoni2
SplunkTrust
SplunkTrust

This might help

index=_internal sourcetype=splunkd group=per_host_thruput | timechart sum(kb) as totalkb by series limit=0

feickertmd
Communicator

This is good, but it gives the average per event. I need aggregate average per day.

I combined yours with the elements here: http://answers.splunk.com/answers/79026/average-count-by-day.html

That worked out nicely. Final query looks like this:
index=_internal sourcetype=splunkd group=per_host_thruput earliest=-1mon@mon latest=@mon | bucket _time span=1d | stats sum(kb) as total by series,_time | stats avg(total) as average by series
|eval averageMB=round(average/1024,2)
|fields - average
|rename series as "Host Server",averageMB as "Average size per day in MB"

0 Karma

feickertmd
Communicator

So while this report is nice, It shows only 31 hosts as belonging to the series field. We have 57 hosts overall. Why would I not see them all in this report?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi feickertmd,

use the license usage report for this, see the docs for more details http://docs.splunk.com/Documentation/Splunk/6.2.0/Admin/AboutSplunksLicenseUsageReportView

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...