{"id":1059,"date":"2015-04-20T12:39:03","date_gmt":"2015-04-20T11:39:03","guid":{"rendered":"http:\/\/cdblog.cdstealer.com\/?p=1059"},"modified":"2019-01-08T17:16:41","modified_gmt":"2019-01-08T17:16:41","slug":"useful-splunk-searches","status":"publish","type":"post","link":"https:\/\/cdblog.cdstealer.com\/?p=1059","title":{"rendered":"Useful Splunk searches."},"content":{"rendered":"<p><strong>List all agents and versions :)<\/strong><\/p>\n<blockquote><p>index=_internal source=*metrics.log group=tcpin_connections | eval sourceHost=if(isnull(hostname), sourceHost,hostname) | dedup sourceHost | where sourceIp != sourceHost | table sourceHost sourceIp os version | sort 0 version<\/p><\/blockquote>\n<p><strong>List all sourcetypes and event dates<\/strong><\/p>\n<blockquote><p>| metadata type=sourcetypes index=* | convert ctime(firstTime) ctime(lastTime) | table firstTime lastTime sourcetype | sort +firstTime<\/p><\/blockquote>\n<p><strong>List sources and size<\/strong><\/p>\n<blockquote><p>index=\"_internal\" source=\"*metrics.log\" group=\"per_source_thruput\"| eval GB=kb\/1024\/1024 | chart sum(GB) by series | sort - sum(GB)<\/p><\/blockquote>\n<p><strong>List License days remaining<\/strong><\/p>\n<blockquote><p>| rest \/services\/licenser\/licenses | search group_id=\"enterprise\" status=\"valid\" OR status=\"expired\" | rename group_id as Type | rename splunk_server as \"Splunk Server\" | eval \"Quota (GB)\"=(quota\/1024\/1024\/1024) | eval now=now() | eval \"Days Remaining\"=(expiration_time-now)\/86400 | eval \"Expiration Time\"=strftime(expiration_time, \"%Y-%m-%d \u00a0%H:%M:%S\") | eval \"Days Remaining\"=round('Days Remaining', 0) | table \"Type\" \"Quota (GB)\" \"Expiration Time\" \"Days Remaining\" \"Splunk Server\" status | where 'Days Remaining' &lt; 10<\/p><\/blockquote>\n<p><strong>List index size per day<\/strong><\/p>\n<blockquote><p>index=_internal source=\"*license_usage.log\"<br \/>\n| eval indexname = if(len(idx)=0 OR isnull(idx),\"(UNKNOWN)\",idx)<br \/>\n| eval sourcetypename = st<br \/>\n| bin _time span=1d<br \/>\n| stats values(poolsz) as poolsz sum(b) as b by _time, pool, indexname, sourcetypename<br \/>\n| eval GB=(b\/1024\/1024\/1024)<br \/>\n| eval pool=(poolsz\/1024\/1024\/1024)<br \/>\n| fields _time, indexname, sourcetypename, GB, pool<br \/>\n| search indexname=* sourcetypename=*<br \/>\n| stats sum(GB) as GB by _time indexname<br \/>\n| eval GB = round(GB,4)<\/p><\/blockquote>\n<p><strong>List index size per indexer<\/strong><\/p>\n<blockquote><p>| rest \/services\/data\/indexes<br \/>\n| where disabled = 0<br \/>\n| search title= \"wh_aws\"<br \/>\n| eval currentDBSizeGB = round( currentDBSizeMB \/ 1024)<br \/>\n| where currentDBSizeGB &gt; 0<br \/>\n| eval maxTotalDataSizeMB = round( maxTotalDataSizeMB \/ 1024)<br \/>\n| eval frozenTimePeriodInSecs= round( frozenTimePeriodInSecs \/ 60 \/60\/ 24)<br \/>\n| eval first_event=strptime(minTime,\"%Y-%m-%dT%H:%M\")<br \/>\n| eval last_event=strptime(maxTime,\"%Y-%m-%dT%H:%M\")<br \/>\n| eval TimeDiff=last_event-first_event | eval TimeDiff = round(TimeDiff\/60\/60\/24,2)<br \/>\n| table splunk_server title summaryHomePath_expanded minTime maxTime currentDBSizeGB totalEventCount frozenTimePeriodInSecs maxTotalDataSizeMB TimeDiff<br \/>\n| eval diff=(latest-earliest)<br \/>\n| rename minTime AS earliest maxTime AS latest summaryHomePath_expanded AS index_path currentDBSizeGB AS Size(GB) totalEventCount AS Count frozenTimePeriodInSecs AS Days maxTotalDataSizeMB AS \"Max(GB)\" title AS index TimeDiff as \"Duration\"<\/p><\/blockquote>\n<p><strong>List users<\/strong><\/p>\n<blockquote><p>|rest \/services\/authentication\/users splunk_server=local |fields title type realname email roles | nomv roles| rename title as Username type as Authentication realname as \"Full Name\" email as Email roles as Roles<\/p><\/blockquote>\n<p><strong>List sourcetypes where data is older than X<\/strong><\/p>\n<blockquote><p>| tstats latest(_time) as latest where index=* by sourcetype host index | where latest &lt; relative_time(now(), \"-4h\") | convert ctime(latest)<\/p><\/blockquote>\n<p><span style=\"color: #000000;\"><strong>List indexes on remote search head<\/strong><\/span><\/p>\n<blockquote><p>| rest \/services\/data\/indexes | search NOT (title=\"_*\" OR title=\"history\" OR title=\"summary\" OR title=\"example\" OR title=\"main\" OR title=\"splunklogger\") | dedup title | table title currentDBSizeMB maxTotalDataSizeMB totalEventCount minTime maxTime<\/p><\/blockquote>\n<p># Find top hosts<\/p>\n<blockquote><p>| tstats count by host | eventstats sum(count) as total | eval percentage = round(count\/total*100,0) | fields - total | sort - count | head 40<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>List all agents and versions :) index=_internal source=*metrics.log group=tcpin_connections | eval sourceHost=if(isnull(hostname), sourceHost,hostname) | dedup sourceHost | where sourceIp != sourceHost | table sourceHost sourceIp os version | sort 0 version List all sourcetypes and event dates | metadata type=sourcetypes index=* | convert ctime(firstTime) ctime(lastTime) | table firstTime lastTime sourcetype | sort +firstTime List sources &hellip; <a href=\"https:\/\/cdblog.cdstealer.com\/?p=1059\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Useful Splunk searches.<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[305],"tags":[212,215],"class_list":["post-1059","post","type-post","status-publish","format-standard","hentry","category-splunk","tag-search","tag-splunk"],"_links":{"self":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts\/1059","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1059"}],"version-history":[{"count":17,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts\/1059\/revisions"}],"predecessor-version":[{"id":1927,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts\/1059\/revisions\/1927"}],"wp:attachment":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1059"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1059"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}