|
Is there anyway to count the number of searches ran on an indexer in a 24 hour period? |
|
The following gives you a total for all adhoc searches run in the past 24 hours:
And this one will give you a total for all searches, including saved searches run in the past 24 hours:
And individual counts by user:
|
|
In the Search App in the Status > Search activity dashboards in Splunk 4.1.x there are dashboards containing the following searches:
If you have SplunkWeb running on the indexer these dashboards will display results for that indexer. I'm not sure if these dashboards are built out of the box for distributed search though. |
