Splunk Search

totalCount in |metadata command: current number of events or lifetime count of events?

Jason
Motivator

Is the number of events reported as totalCount in | metadata...

  • the lifetime running total of the events for that (source|sourcetype|host), so the number only goes up

... or ...

  • the current total, so the number could go up and down once buckets start rolling out of indexes?
Tags (1)

rshoward
Path Finder

UPDATE: It is a total indexed over lifetime counter. I ran the trend on a huge data set that has a full index that is cycling out old events. For the last week the totalCount for all assets have only been increasing. The numbers also differ in the billions from the index stats when added up.

----original----

My initial test shows it is the "current total" you speak of; meaning it could go up and down. I'm running another test now with a larger set of data then I'll let you know once I ingest more from another host which should reduce the value of totalCount when the limit is hit. (I have a trend running on that value per host so it should dip once I complete these bulk tests)

0 Karma

rshoward
Path Finder

Jason, sorry for the delay. I let the trend run for a week just to be sure. I've update the answer with my findings.

0 Karma

Jason
Motivator

Thanks. Do you have a result from that larger data set?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...