Greetings,
I am trying to figure out whether data under a given source type is growing. I would like to get these results grouped into days for each source type:
*| stats count by sourcetype
So a chart would have the 8 source types I have grow or shrink by day.
Thanks for your help!
Dave
for the count of events :
* | timechart span=1d limit=10 count by sourcetype
or for the volume, see http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume
for the count of events :
* | timechart span=1d limit=10 count by sourcetype
or for the volume, see http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume
Thanks Yann!
I ended up with:
*| timechart span=6h count by sourcetype
Cheers!