How to determine sum of data usage (storage) for parsed searches

Comments

1 comment

  • Avatar
    Christian

    try this:

    _sourceCategory=app_service | parse "* * * * *+* [*] *  * - *" as iso_time,hostname,log_type,dater,time,timezone,service_type,syslog_level,java_app,other | count, sum(_size) as sum_size by hostname,java_app | sort by sum_size | (sum_size  / 1024 / 1024) as sum_size_mb | (sum_size_mb / 1024) as sum_size_gb

    _size has the size in bytes of the raw message.

    if you need to run this over larger periods of time and/or more often, consider turning the query into a scheduled view.

     

    chr.

    0
    Comment actions Permalink

Please sign in to leave a comment.