I have 10 indexes...i want to find the actual size of the index before splunk adding its indexing.
and after as well.
You need dbinspect
and the rawSize
field:
https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/SearchReference/Dbinspect
Try this:
|dbinspect index=a OR index=b OR ... OR index=z | table index rawSize
You might also check out the Fire Brigade
app:
https://splunkbase.splunk.com/app/1632/
Or your Monitoring Console
:
https://docs.splunk.com/Documentation/Splunk/6.6.1/DMC/DMCoverview
You need dbinspect
and the rawSize
field:
https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/SearchReference/Dbinspect
Try this:
|dbinspect index=a OR index=b OR ... OR index=z | table index rawSize
You might also check out the Fire Brigade
app:
https://splunkbase.splunk.com/app/1632/
Or your Monitoring Console
:
https://docs.splunk.com/Documentation/Splunk/6.6.1/DMC/DMCoverview
Thanks ..I think I should look do a course to become SPlunk Admin...
From sample Query started (Just write Query and that is the end...)---> dont know how far i will go into SPlunk
Look at the dbinspect command.
https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/SearchReference/Dbinspect
thanks -- sorry been busy with wrk