Need a search string to find MB indexed per 24 hour by a specific host. Can someone send an example?
I use this search to get a chart of per-host indexing volume:
index="_internal" source="*metrics.log" per_host_thruput | chart sum(kb) by series
An easy change to that is to search by the hostname in the series field:
index="_internal" source="*metrics.log" per_host_thruput series=some-host-name | stats sum(kb)
For extra fun, lets look at 30 day trends:
index="_internal" source="*metrics.log" per_host_thruput series=some-host-name earliest=-30d@d latest=@d | timechart span=1d sum(kb)
If the host is in the top 10 hosts of traffic, you can do:
index=_internal source=*metrics.log* per_host_thruput <hostname> | eval mb=kb/1024 | timechart span=1d sum(mb) as Total
If it is not in the top 10 hosts, you will have to do a raw length search that can be expensive. So something like:
host=<hostname> | eval size=len(_raw) | timechart span=1d sum(size) | addtotals
app/search/indexing_volume ?