Splunk search for Hot, warm and cold buckets by index

Copy
|dbinspect index=* | search index!=_* | eval state=case(state=="warm" OR state=="hot","hot/warm",1=1, state) | chart dc(bucketId) over index by state
This Splunk search will provide the total count of all buckets currently in your Splunk environment. The search sums hot and warm buckets together. The search will show the number of buckets separated out by index.
0 comments

Category:

General Splunk


Tags:

general Admin dbinspect

Search Commands:

Sign in or Register to submit a comment