|
is there a query to get the size of a log event (how big the event is inside splunk?) I know you can get index sizes, just want to try to break it up a bit more. I can't find a field that is "size of log entry". |
|
You should be able to use the
Note: You asked about the "size" of your event. However, the term "size" is a bit ambigious. This example shows you the number of characters in the |
|
What does it returns exactly ? What are the columns p10 and p90 ?? Is it the size in Mo ? |