<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Metadata and tstats give different sources: How do I get the list of sources based on the tstats result? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Metadata-and-tstats-give-different-sources-How-do-I-get-the-list/m-p/589095#M103340</link>
    <description>&lt;P&gt;Make sure you are running both searches in the same time range.&lt;/P&gt;&lt;P&gt;Otherwise, I don't see any reason for them to show different results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;how can I search for all the increments of the source if I know what it is?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;* You can use the search with metadata command.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;* But you generally don't need it because Splunk will always monitor&amp;nbsp;tortor-adaptor.log file not the rolled over filed (tortor-adaptor.log.1,&amp;nbsp;tortor-adaptor.log.2, etc)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;* So when you start logging for the first time only at that time it will monitor rolled-over files.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Mar 2022 13:34:34 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2022-03-15T13:34:34Z</dc:date>
    <item>
      <title>Metadata and tstats give different sources: How do I get the list of sources based on the tstats result?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Metadata-and-tstats-give-different-sources-How-do-I-get-the-list/m-p/588913#M103319</link>
      <description>&lt;P&gt;I have two search queries:&lt;/P&gt;
&lt;PRE&gt;| metadata index=* type=sources&lt;/PRE&gt;
&lt;P&gt;that results in something like the following (under the &lt;EM&gt;source&lt;/EM&gt; field)&lt;/P&gt;
&lt;PRE&gt;/lorem/ipsum/dolor/sit/tortor-adaptor.log&lt;BR /&gt;/lorem/ipsum/dolor/sit/tortor-adaptor.log.1&lt;BR /&gt;/lorem/ipsum/dolor/sit/tortor-adaptor.log.10&lt;BR /&gt;/lorem/ipsum/dolor/sit/tortor-adaptor.log.11&lt;BR /&gt;/lorem/ipsum/dolor/sit/tortor-adaptor.log.12&lt;BR /&gt;/lorem/ipsum/dolor/sit/tortor-adaptor.log.13&lt;BR /&gt;/lorem/ipsum/dolor/sit/tortor-adaptor.log.14&lt;BR /&gt;/lorem/ipsum/dolor/sit/tortor-adaptor.log.15&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;then there's the following search&lt;/P&gt;
&lt;PRE&gt;| tstats values(source) where index=*&lt;/PRE&gt;
&lt;P&gt;that produces something like the following (under the &lt;EM&gt;values(source)&lt;/EM&gt; field)&lt;/P&gt;
&lt;PRE&gt;/lorem/ipsum/dolor/sit/tortor-adaptor.log&lt;BR /&gt;/lorem/ipsum/nunc-test.log.1&lt;BR /&gt;/lorem/ipsum/dolor/sit/pulvinar/ex-eros.log&lt;BR /&gt;/comsed/ipsum/dolor/ut-eget.log&lt;BR /&gt;/donec/sit/nam-libero.log.1&lt;BR /&gt;/aliquet/ipsum/dolor/sit/vel-arcu.log&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why is Splunk showing me different results?&lt;/P&gt;
&lt;P&gt;Also, how can I search for all the increments of the source if I know what it is? For example, if I have "/lorem/ipsum/dolor/sit/tortor-adaptor.log" how can I find all of its increments (e.g. "/lorem/ipsum/dolor/sit/tortor-adaptor.log.1,&amp;nbsp;/lorem/ipsum/dolor/sit/tortor-adaptor.log.2,&amp;nbsp;/lorem/ipsum/dolor/sit/tortor-adaptor.log.3")?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 19:28:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Metadata-and-tstats-give-different-sources-How-do-I-get-the-list/m-p/588913#M103319</guid>
      <dc:creator>yaharga</dc:creator>
      <dc:date>2022-03-14T19:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Metadata and tstats give different sources: How do I get the list of sources based on the tstats result?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Metadata-and-tstats-give-different-sources-How-do-I-get-the-list/m-p/589095#M103340</link>
      <description>&lt;P&gt;Make sure you are running both searches in the same time range.&lt;/P&gt;&lt;P&gt;Otherwise, I don't see any reason for them to show different results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;how can I search for all the increments of the source if I know what it is?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;* You can use the search with metadata command.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;* But you generally don't need it because Splunk will always monitor&amp;nbsp;tortor-adaptor.log file not the rolled over filed (tortor-adaptor.log.1,&amp;nbsp;tortor-adaptor.log.2, etc)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;* So when you start logging for the first time only at that time it will monitor rolled-over files.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 13:34:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Metadata-and-tstats-give-different-sources-How-do-I-get-the-list/m-p/589095#M103340</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-03-15T13:34:34Z</dc:date>
    </item>
  </channel>
</rss>

