All templates

Automated Splunk Ingest Volume Monitoring

Every morning, WebRun opens Splunk, reads yesterday's daily indexing volume against your licence quota, breaks it down by index and sourcetype, compares each against its recent average, texts you through Twilio when one has spiked, and posts the full breakdown to Telegram for the platform team.

Runs on WebRun · Strict Lockdown policy
Every day at 7:00 AM WebRunorchestrates each step
1 Splunk read yesterday's ingest against quota
2 Twilio text you when a sourcetype spikes
3 Telegram post the daily breakdown
In short

How do I find which sourcetype is driving my Splunk ingest up?

WebRun watches your Splunk ingest every morning. It reads yesterday's daily indexing volume against your licence quota, breaks it down by index and sourcetype, compares each against its recent average, texts you through Twilio when one spikes, and posts the full breakdown to Telegram.

  • A spike is attributed to an index and sourcetype the next morning
  • Quota headroom is known daily instead of at renewal
  • Noisy new forwarders are caught before they cost an overage

Built for Splunk admins · platform engineers · SRE teams · security operations

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens splunk.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Splunk - read yesterday's ingest against quota
    splunk.com
    WebRun in Splunk: read yesterday's ingest against quota
    WebRun opens Splunk to read yesterday's ingest against quota.
    • Open Splunk and read yesterday's total daily indexing volume
    • Compare it against your licence quota and note the headroom left
    • Break the volume down by index and by sourcetype
    • Compare each sourcetype against its recent daily average and flag the growers
    • Check whether a forwarder started sending far more than usual

    Done when Yesterday's volume is measured against quota and attributed to indexes and sourcetypes.

  3. 2
    Twilio - text you when a sourcetype spikes
    twilio.com
    WebRun in Twilio: text you when a sourcetype spikes
    WebRun opens Twilio to text you when a sourcetype spikes.
    • Text the platform owner when yesterday's volume passes your warning threshold
    • Text as well when a single sourcetype grows past its usual band
    • Name the index, the sourcetype and the volume in the message
    • Send nothing on a normal day so a text always means something

    Done when The platform owner has been texted about any spike.

  4. 3
    Telegram - post the daily breakdown
    telegram.org
    WebRun in Telegram: post the daily breakdown
    WebRun opens Telegram to post the daily breakdown.
    • Post the daily ingest breakdown to your platform channel
    • Lead with total volume, quota and percentage used
    • List the top indexes and sourcetypes by volume with their change against average
    • Name the forwarders behind any new growth so the source is obvious

    Done when The platform channel has yesterday's ingest breakdown.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
splunk.com
ScheduleRuns automatically on this cadence
Every day at 7:00 AM
DeliveryHow each run's result reaches you
Ingest breakdown · Telegram
OutputWhat each run produces - A daily ingest breakdown: total volume against quota, the top indexes and sourcetypes, and how each compares with its recent average.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Does it change any Splunk configuration?

No. WebRun only reads volume figures, indexes, sourcetypes and forwarder activity. It never edits an index, adds a filter, or changes a licence setting, so nothing about ingestion changes.

How does it decide something has spiked?

It compares each sourcetype against its own recent daily average and against the warning threshold you set on total volume, so normal seasonal variation does not trigger a text.

Will it wake me up for a small change?

No. Texts only go out when total volume passes your threshold or a sourcetype breaks out of its usual band. Ordinary days get the Telegram breakdown and nothing else.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.