All Apps and Add-ons

How to find the average number of events per day using Splunk on Splunk app metrics in Splunk?

shellnight
Explorer

how i can find the average number of events per day using SOS app metrics in splunk ?

the search index=* | timechart span=1d count as dailycount takes hours and hangs

0 Karma

somesoni2
Revered Legend

Try this

index=_internal sourcetype=splunkd group=per_index_thruput |timechart span=1d sum(ev) as dailycount
0 Karma

shellnight
Explorer

Update please

0 Karma

shellnight
Explorer

Get the below error
Error in 'timechart' command: The specifier 'sum' is invalid. It must be in form (). For example: max(size).

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...