Run the following search over the time range real-time(all time) and you will be able to see what your incoming event rate looks like :
index=savage_clowns | eval search_time=now() | eval seconds_elapsed=(time() - search_time) | eval secs=if(seconds_elapsed<0,"1",seconds_elapsed) | stats count as ecount, last(secs) AS seconds| stats last(ecount) AS "event count", last(seconds) AS "search seconds elapsed", last(eval(ecount/seconds)) AS eps
This example targets a specific index, but feel free to change the first search terms to better suit your needs.
Run the following search over the time range real-time(all time) and you will be able to see what your incoming event rate looks like :
index=savage_clowns | eval search_time=now() | eval seconds_elapsed=(time() - search_time) | eval secs=if(seconds_elapsed<0,"1",seconds_elapsed) | stats count as ecount, last(secs) AS seconds| stats last(ecount) AS "event count", last(seconds) AS "search seconds elapsed", last(eval(ecount/seconds)) AS eps
This example targets a specific index, but feel free to change the first search terms to better suit your needs.
savage_clowns killed me 😄 nice