Splunk will track the top 10 inputs based on source and host. To retrieve that information, you could run the following search:
index=_internal source=*metrics.log* per_host_thruput | timechart sum(kb) by series
To increase the number of tracked inputs, you can set that in your limits.conf file for metrics tracking.
how about this:
index="_internal" source="*metrics.log*" per_host_thruput | timechart max(kbps) by series | addtotals
I am monitoring a cluster of servers and am trying to capture the network thruput by host. I know splunk has a basic one out of the box. Thrput_by_host(*)
. However, I would like to be able to pinpoint the thruput of each server. When I attempted to hone the search, I couldn't get any data back. For example
Thruput_by_host(*) | timechart span=24h avg(Thruput_by_host()) as AvgHostThruput, AvgHostThruput renders nothing.
Your question is not very clear without any information about the data source (input).