Hi,
Anyone know a summary index used by Splunk to retain the index sizes? I can calculate a index size by using internal index but I need to go back further than the last month.
Any other method is welcomed as well.
Thanks
Apart from finding the information (the _internal index by default rolls after 30 days), the trouble with "index sizes" is that there are so many different parameters which can be meant as "index size".
Even simple dbinspect has two different parameters (rawSize and sizeOnDiskMB). Add to this summary and datamodel_summary directories...
Try the summary index and look for either source=splunk-storage-detail or source=splunk-storage-summary, depending on what you are looking for.
Thanks @richgalloway
I was able to see some data using the source mentioned below. However the "rawSizeBytes" field does not match the index size when converted to GB.
source=splunk-storage-detail