<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how - metadata host by index and  sourcetype recentTime in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162981#M33036</link>
    <description>&lt;P&gt;This search produces the most recent timestamp for every host for aa specific index&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;| metadata type=hosts index=windows |&lt;BR /&gt;
convert ctime(*Time) | table host&lt;BR /&gt;
index recentTime&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;how can i break it down a level further by last tinme a host reported in for a given sourcetype and index?&lt;/P&gt;

&lt;P&gt;eg&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;PRE&gt;&lt;CODE&gt;    host   index    sourcetype   recenttime
    host1  windows   system      30/06/2014 04:55
    host1  windows   security    30/06/2014 05:15
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Wed, 30 Jul 2014 09:18:06 GMT</pubDate>
    <dc:creator>robf</dc:creator>
    <dc:date>2014-07-30T09:18:06Z</dc:date>
    <item>
      <title>how - metadata host by index and  sourcetype recentTime</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162981#M33036</link>
      <description>&lt;P&gt;This search produces the most recent timestamp for every host for aa specific index&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;| metadata type=hosts index=windows |&lt;BR /&gt;
convert ctime(*Time) | table host&lt;BR /&gt;
index recentTime&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;how can i break it down a level further by last tinme a host reported in for a given sourcetype and index?&lt;/P&gt;

&lt;P&gt;eg&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;PRE&gt;&lt;CODE&gt;    host   index    sourcetype   recenttime
    host1  windows   system      30/06/2014 04:55
    host1  windows   security    30/06/2014 05:15
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Wed, 30 Jul 2014 09:18:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162981#M33036</guid>
      <dc:creator>robf</dc:creator>
      <dc:date>2014-07-30T09:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: how - metadata host by index and  sourcetype recentTime</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162982#M33037</link>
      <description>&lt;P&gt;Hello Rob,&lt;BR /&gt;
If you are on Splunk 6 @martin_mueller 's answer will help you get the info.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/145995/alert-if-source-stops-indexing"&gt;http://answers.splunk.com/answers/145995/alert-if-source-stops-indexing&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Or &lt;/P&gt;

&lt;P&gt;you can maintain a lookup table and make the comparison with metadata.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
L&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 10:08:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162982#M33037</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-07-30T10:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: how - metadata host by index and  sourcetype recentTime</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162983#M33038</link>
      <description>&lt;P&gt;metadata type=hosts doesn't contain sourcetye information. &lt;/P&gt;

&lt;P&gt;Check this&lt;/P&gt;

&lt;P&gt;&lt;A href="http://"&gt;http://answers.splunk.com/answers/10005/how-to-get-host-sourcetype-and-source-from-a-single-metadata-search&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You may need different combinations. This link &lt;A href="http://"&gt;http://answers.splunk.com/tags/metadata/&lt;/A&gt; has questions tagged with metadata. Some of these may help you.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 10:18:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162983#M33038</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-07-30T10:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: how - metadata host by index and  sourcetype recentTime</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162984#M33039</link>
      <description>&lt;P&gt;|metasearch index=* sourcetype=* host=* | table index sourcetype host&lt;/P&gt;

&lt;P&gt;This wont fetch recentTime&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 10:27:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162984#M33039</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-07-30T10:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: how - metadata host by index and  sourcetype recentTime</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162985#M33040</link>
      <description>&lt;P&gt;There is no in-build metadata which gives this information grouped by index, sourcetype and host all. &lt;/P&gt;

&lt;P&gt;You can try this to get the the timestamp of last written entry for index, sourcetype host combination. This is the fastest available search I believe for this requirement (other than @martin's which is specific to Splunk6).&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|metasearch index=clm_transactions sourcetype=* host=* | stats max(_time) as recentTime by index sourcetype host
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;select appropriate time range for the search so that you can cover most of the host. It won't report for the hosts which have written any entries in given time range.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 15:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-metadata-host-by-index-and-sourcetype-recentTime/m-p/162985#M33040</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-30T15:11:53Z</dc:date>
    </item>
  </channel>
</rss>

