Total Data Volume for All Partitions & Scheduled Views


1 comment

  • Avatar
    Noah Sussman
    Thanks, this is exactly what I was looking for!

    The search didn't work for me exactly as written. This is the query I wound up using:

     _index=sumologic_volume and sizeInBytes and _sourceCategory="view_volume"
    | parse regex "\"(?<Source>[^\"]*)\"\:\{\"sizeInBytes\"\:(?<bytes>\d+)" multi
    | sum(bytes) by Source
    | _sum/1024/1024/1024/1024 as Terabytes
    | sort by Terabytes
    Comment actions Permalink

Please sign in to leave a comment.