Splunk Dev

How do I build a report with total events For SMS?

noviceinsplunk
New Member

At the end of the day, is it feasible to tally the number of successful events to compare with yesterday’s total without too much performance overhead?

It seems this would run for a long time.

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi,

  • Is it feasible to tally number of successful events, at the end of day, to compare with yesterday’s total; without performance overhead?

Answer: Yes, it's not a performance overhead at all, depending on your logs/event volume.

Please provide us the search query for today's logs.. check the volume for one day..
if the size is huge, then you can choose summary indexing..

overall, it "appears" to be a feasible task.

and, SMS meaning?

0 Karma

noviceinsplunk
New Member

Text or PUSH message too.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...