Install the Sizing Inputs Calculator for Splunk in accordance to the documentation for a Single Server Install.
This app uses a search macro to easily select the earliest time (in days) that the searches should look back. The macro is called
earliest and it is currently set to look back 7 days by default.
For example, the
Daily Search Count search utilizes the
earliest search macro:
latest=@d index=_audit host=* action=search sourcetype=audittrail search_id!="*rsa_*" search_id!="*subsearch*"
| timechart span=1d dc(search_id) AS "Daily Search Count"
| stats perc95("Daily Search Count") AS "Daily Search Count"
earliest macro can easily be edited to change to look back a different time range that that set by default:
earliestmacro and change its definition (
earliest=-7day@day) as desired
After installing the Sizing Inputs Calculator for Splunk, users can navigate to the Sizing Inputs Calculator for Splunk app to view a dashboard that renders sizing information about the deployment. Users should share this information back to their Splunk Account team by exporting the dashboard as a PDF.
There are no known issues at this time.
Click on the “Questions on Splunk Answers” link on the right side to post any questions.
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.