When I select the "source" dropdown in the Universal Field Extractor app, it doesn't display all of the sources associated with the index I've restricted the extraction to. I tried to look at the code, but it's Python and 1280 lines worth of code that I didn't feel comfortable messing with. I assume the search may only be going back 5 minutes or 15 minutes or something and not doing a complete search of all available results, just to finish quickly.
Any ideas?
Thanks!
Try the _bump
and refresh
endpoints:
http://docs.splunk.com/Documentation/Splunk/6.5.2/AdvancedDev/CustomizationOptions