<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to find out which source, source type and host are not getting data into Splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-out-which-source-source-type-and-host-are-not/m-p/438504#M124785</link>
    <description>&lt;P&gt;You could look at some the the below answers and create one that suits your need. You can use metadata or metasearch, which is widely used for a resonable sized deployments.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/3181/how-do-i-alert-when-a-host-stops-sending-data.html"&gt;https://answers.splunk.com/answers/3181/how-do-i-alert-when-a-host-stops-sending-data.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/435074/is-there-a-dashboard-to-monitor-when-event-data-is.html"&gt;https://answers.splunk.com/answers/435074/is-there-a-dashboard-to-monitor-when-event-data-is.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/89020/query-for-host-not-sending-sourcetype.html"&gt;https://answers.splunk.com/answers/89020/query-for-host-not-sending-sourcetype.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Aug 2019 10:32:31 GMT</pubDate>
    <dc:creator>lakshman239</dc:creator>
    <dc:date>2019-08-12T10:32:31Z</dc:date>
    <item>
      <title>How to find out which source, source type and host are not getting data into Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-out-which-source-source-type-and-host-are-not/m-p/438503#M124784</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;In my environment having a huge number of host, source and source types. From some of the host or source or source type, we are not getting data. Wanted to find which host or source or source type not sending data into Splunk and from what time onwards host, source, source type not sending data. Wanted to see in a table like below format&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Host | Source | Source Type | Data not Coming In | Time&lt;/STRONG&gt;(from what time onwards data is not coming )&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2019 01:59:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-out-which-source-source-type-and-host-are-not/m-p/438503#M124784</guid>
      <dc:creator>Reddi694325</dc:creator>
      <dc:date>2019-08-12T01:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to find out which source, source type and host are not getting data into Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-out-which-source-source-type-and-host-are-not/m-p/438504#M124785</link>
      <description>&lt;P&gt;You could look at some the the below answers and create one that suits your need. You can use metadata or metasearch, which is widely used for a resonable sized deployments.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/3181/how-do-i-alert-when-a-host-stops-sending-data.html"&gt;https://answers.splunk.com/answers/3181/how-do-i-alert-when-a-host-stops-sending-data.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/435074/is-there-a-dashboard-to-monitor-when-event-data-is.html"&gt;https://answers.splunk.com/answers/435074/is-there-a-dashboard-to-monitor-when-event-data-is.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/89020/query-for-host-not-sending-sourcetype.html"&gt;https://answers.splunk.com/answers/89020/query-for-host-not-sending-sourcetype.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2019 10:32:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-out-which-source-source-type-and-host-are-not/m-p/438504#M124785</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-08-12T10:32:31Z</dc:date>
    </item>
  </channel>
</rss>

