Hello, we are trying to work out how much data our Splunk instances search through on average.
so we've written a search that tells us our platform is running 75-80,000 searches a day, this would be only a few manual searches and the rest coming from saved / correlation searches. Is there anywhere in the system or a search we can write that would say for instance these 75,000 searches, searched through a total of 750gb of data...
We are researching the possibility of moving to a platform that costs per search, so if we can get these figures we can see how much a like for like replacement would actually cost.