After experiencing our own version of user quota issues addressed in other questions, I want to execute a search in Splunk for
- how much space is used by (a given set of) users
- what are those users' quota
Splunk knows the values since it enforces the quota, and it will display the current usage and quota to over-quota users. However, I have not found how to access this. Nor have I seen how to calculate sizes of enough components (such as indexes) to build the search myself. The biggest item I can't find is saved searches.
What search(es) in Splunk show this information? Thanks.