Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Alert if Index is getting more than 10GB of incoming data

$
0
0
I am using below query to find size of index , how can I modify it to alert me if index is getting more than 10 GB of incoming data index=_internal [`set_local_host`] source=*license_usage.log* type="Usage" idx="*"| eval MB = round(b/1048576,2) | eval st_idx = st.": ".idx | timechart span=1d sum(MB) by st_idx | addtotals

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>