Splunk : 計算log檔案在Splunk所佔的大小

  1. 計算檔案空間
    Splunk 語法:
    source="/home/splunk_input_data/imss/2014/log.imss.20141019.0002" | eval esize=len(_raw) | stats sum(esize) AS sum_esize, count | eval fsize=sum_esize + count | fields fsize
    Linux指令:
    grep -v -e "^s*$" /home/splunk_input_data/imss/2014/log.imss.20141019.0002 | wc -c

  2. 計算筆數
    Splunk 語法:
    source="/home/splunk_input_data/imss/2014/log.imss.20141019.0002" | stats sum(linecount)
    Linux指令:
    grep -v -e "^s*$" /home/splunk_input_data/imss/2014/log.imss.20141019.0002 | wc -l

This entry was posted in Linux, Splunk. Bookmark the permalink.