splunk.aggregation.queue.ratio | gauge | double | {%} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the average indexer aggregation queue ration (%). *Note:** Search is best run against a Cluster Manager. |
splunk.buckets.searchable.status | gauge | int | {count} | development | no | splunk.host (string), splunk.indexer.searchable (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the number of buckets and their searchable status. *Note:** Search is best run against a Cluster Manager. |
splunk.data.indexes.extended.bucket.count | gauge | int | {buckets} | development | no | splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Count of buckets per index |
splunk.data.indexes.extended.bucket.event.count | gauge | int | {events} | development | no | splunk.bucket.dir (string), splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Count of events in this bucket super-directory. *Note:** Must be pointed at specific indexer endpoint. |
splunk.data.indexes.extended.bucket.hot.count | gauge | int | {buckets} | development | no | splunk.bucket.dir (string), splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | (If size > 0) Number of hot buckets. *Note:** Must be pointed at specific indexer endpoint. |
splunk.data.indexes.extended.bucket.warm.count | gauge | int | {buckets} | development | no | splunk.bucket.dir (string), splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | (If size > 0) Number of warm buckets. *Note:** Must be pointed at specific indexer endpoint and gathers metrics from only that indexer. |
splunk.data.indexes.extended.event.count | gauge | int | {events} | development | no | splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Count of events for index, excluding frozen events. Approximately equal to the event_count sum of all buckets. *Note:** Must be pointed at specific indexer endpoint and gathers metrics from only that indexer. |
splunk.data.indexes.extended.raw.size | gauge | int | By | development | no | splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Size in bytes on disk of the <bucket>/rawdata/ directories of all buckets in this index, excluding frozen *Note:** Must be pointed at specific indexer endpoint and gathers metrics from only that indexer. |
splunk.data.indexes.extended.total.size | gauge | int | By | development | no | splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Size in bytes on disk of this index *Note:** Must be pointed at specific indexer endpoint and gathers metrics from only that indexer. |
splunk.health | gauge | int | {status} | development | yes | splunk.feature (string), splunk.feature.health (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | The status ('red', 'yellow', or 'green') of the Splunk server. Health of 'red' produces a 0 while all other colors produce a 1. |
splunk.indexer.avg.rate | gauge | double | kBy | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the average rate of indexed data. Note: Search is best run against a Cluster Manager. |
splunk.indexer.cpu.time | gauge | double | {s} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the number of indexing process cpu seconds per instance |
splunk.indexer.queue.ratio | gauge | double | {%} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the average indexer index queue ration (%). *Note:** Search is best run against a Cluster Manager. |
splunk.indexer.raw.write.time | gauge | double | {s} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the number of raw write seconds per instance |
splunk.indexer.rollingrestart.status | gauge | int | {status} | development | no | splunk.rollingorrestart (bool), splunk.searchable.restart (bool), splunk.splunkd.build (string), splunk.splunkd.version (string) | The status of a rolling restart. |
splunk.indexer.throughput | gauge | double | By/s | development | no | splunk.indexer.status (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking average bytes per second throughput of indexer. *Note:** Must be pointed at specific indexer endpoint and gathers metrics from only that indexer. |
splunk.indexes.avg.size | gauge | double | Gb | development | no | splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the indexes and their average size (gb). *Note:** Search is best run against a Cluster Manager. |
splunk.indexes.avg.usage | gauge | double | {%} | development | no | splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the indexes and their average usage (%). *Note:** Search is best run against a Cluster Manager. |
splunk.indexes.bucket.count | gauge | int | {count} | development | no | splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the indexes and their bucket counts. *Note:** Search is best run against a Cluster Manager. |
splunk.indexes.median.data.age | gauge | int | {days} | development | no | splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the indexes and their median data age (days). *Note:** Search is best run against a Cluster Manager. |
splunk.indexes.size | gauge | double | Gb | development | no | splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the indexes and their total size (gb). *Note:** Search is best run against a Cluster Manager. |
splunk.io.avg.iops | gauge | int | {iops} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the average IOPs used per instance |
splunk.kvstore.backup.status | gauge | int | {status} | development | no | splunk.kvstore.status.value (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Backup and restore status of the KV store. |
splunk.kvstore.replication.status | gauge | int | {status} | development | no | splunk.kvstore.status.value (string), splunk.kvstore.storage_engine (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Replication status of the KV store. |
splunk.kvstore.status | gauge | int | {status} | development | no | splunk.kvstore.external (string), splunk.kvstore.status.value (string), splunk.kvstore.storage_engine (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | This is the overall status of the kvstore for the given deployment. |
splunk.license.expiration.seconds_remaining | gauge | int | {seconds} | development | no | splunk.license.label (string), splunk.license.status (string), splunk.license.type (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the seconds remaining on any given Splunk License found via Splunk API. Note: This will only work on a Cluster Manager. |
splunk.license.index.usage | gauge | int | By | development | no | splunk.index.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the indexed license usage per index |
splunk.parse.queue.ratio | gauge | double | {%} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the average indexer parser queue ration (%). *Note:** Search is best run against a Cluster Manager. |
splunk.pipeline.set.count | gauge | int | kBy | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the number of pipeline sets per indexer. Note: Search is best run against a Cluster Manager. |
splunk.scheduler.avg.execution.latency | gauge | double | {ms} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the average execution latency of scheduled searches |
splunk.scheduler.avg.run.time | gauge | double | {ms} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the average runtime of scheduled searches |
splunk.scheduler.completion.ratio | gauge | double | {%} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the ratio of completed to skipped scheduled searches |
splunk.search.duration | gauge | double | {status} | development | no | splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the duration in seconds of the last search probe call. |
splunk.search.initiation | gauge | int | {status} | development | no | splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking whether the last search probe successfully initiated a search. |
splunk.search.status | gauge | int | {status} | development | no | splunk.search.state (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the dispatch status of the last search probe. |
splunk.search.success | gauge | int | {status} | development | no | splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking whether the last search probe call was successful with the dispatch state 'DONE'. |
splunk.server.introspection.queues.current | gauge | int | {queues} | development | no | splunk.queue.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking current length of queue. *Note:** Must be pointed at specific indexer endpoint and gathers metrics from only that indexer. |
splunk.server.introspection.queues.current.bytes | gauge | int | By | development | no | splunk.queue.name (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking current bytes waiting in queue. *Note:** Must be pointed at specific indexer endpoint and gathers metrics from only that indexer. |
splunk.server.searchartifacts.adhoc | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking number of ad hoc search artifacts currently on disk. Note:* Must be pointed at specific Search Head endpoint and gathers metrics from only that Search Head. Available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.adhoc.size | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge total size (MB) of ad hoc search artifacts currently on disk. Note:* Must be pointed at specific Search Head endpoint and gathers metrics from only that Search Head. Available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.completed | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking number of artifacts currently on disk that belong to finished searches. Note:* Must be pointed at specific Search Head endpoint and gathers metrics from only that Search Head. Available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.completed.size | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge total size (MB) of artifacts currently on disk that belong to finished searches. Note:* Must be pointed at specific Search Head endpoint and gathers metrics from only that Search Head. Available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.incomplete | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking number of artifacts currently on disk that belong to unfinished/running searches. Note:* Must be pointed at specific Search Head endpoint and gathers metrics from only that Search Head. Available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.incomplete.size | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge total size (MB) of artifacts currently on disk that belong to unfinished/running searches. Note:* Must be pointed at specific Search Head endpoint and gathers metrics from only that Search Head. Available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.invalid | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking number of artifacts currently on disk that are not in a valid state, such as missing info.csv file, etc. Note:* Must be pointed at specific Search Head endpoint and gathers metrics from only that Search Head. Available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.job.cache.count | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking number search artifacts metadata stored in memory, available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.job.cache.size | gauge | int | {mb} | development | no | splunk.host (string), splunk.searchartifacts.cache.type (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking, in megabytes, memory used to cache job status and job info of all search artifacts, available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.savedsearches | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking, for the splunk.server.searchartifacts.scheduled number of scheduled search artifacts, how many different saved-searches they belong to. Note:* Must be pointed at specific Search Head endpoint and gathers metrics from only that Search Head. Available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.scheduled | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking number of scheduled search artifacts currently on disk. Note:* Must be pointed at specific Search Head endpoint and gathers metrics from only that Search Head. Available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.server.searchartifacts.scheduled.size | gauge | int | {search_artifacts} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge total size (MB) of scheduled search artifacts currently on disk. Note:* Must be pointed at specific Search Head endpoint and gathers metrics from only that Search Head. Available in builds 9.1.2312.207+ and 9.3.x+. |
splunk.typing.queue.ratio | gauge | double | {%} | development | no | splunk.host (string), splunk.splunkd.build (string), splunk.splunkd.version (string) | Gauge tracking the average indexer typing queue ration (%). *Note:** Search is best run against a Cluster Manager. |