Can you create a query that search for all the logs that got entered in an index for the last 24hours and group it by index? That similar to a table with the number of logs added per index in the period of time you select.
It would be much appreciated thank you so much for your help:)
Try like this (Select appropriate timerange)
| tstats count WHERE index=* by index
This question has a lot of discussion that's similar to your problem. From that, I think the following query will do what you want.
| tstats count values(sourcetype) WHERE index=* BY index
Don't forget about the metadata command - that's another good one to see the latest event received by sourcetype and other ingest monitoring information.
Perfect I will check it out and thank you for your answer!