Hi,
In our instance, we have indexes that have current sizes that are more than the maximum size of the index. We just wanted to create and alert to monitor if an index has data older than the specified retention period. For example, if an index has a retention period of 90 days, it ideally should not have data for the 91st day.
Thanks.
How's this?
| tstats earliest(_time) as firstTime WHERE index=(your index)
How's this?
| tstats earliest(_time) as firstTime WHERE index=(your index)