Speed while trying to quantify log volumes

Comments

2 comments

  • Avatar
    Ben Newton

    Colin,

    That query will be pretty slow. The best thing to do is set up a dashboard tracking messages by collector. Something like: 

    * | timeslice 1d | count by _collector, _timeslice | transpose row _timeslice column _collector

     

    In the longer term, we will have an option to funnel usage back into your account to let you do this more easily.

    0
    Comment actions Permalink
  • Avatar
    Christian

    also, we are in the final stages of preparing for release functionality that will push statistics on the number and size of messages as "logs" back into your account for further analysis. this will be by collector, source, source category, source name, and source host. we will then also work on supplying some content for you to use (searches, dashboards).

    in the meantime, Ben's suggestion is the best way to approach this manually. but i should also point out that we do have the status page, under the manage top level menu - if you are looking for volume by collector, this should help you as well.

     

    chr.

    0
    Comment actions Permalink

Please sign in to leave a comment.