- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a way to have a Dashboard in Splunk that contains a que of latest update of all indexes inside of Splunk?
eyaluodba
Path Finder
06-01-2017
07:13 AM
I want to find a way to have a Dashboard in Splunk that contains a que of latest update of all indexes inside of Splunk.
The main objective is to identify Dashboards containing old information in order to remove all of them. Please let me know if this is possible and if so, how to do it too.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

woodcock
Esteemed Legend
06-01-2017
01:18 PM
Try the Meta Woot!
app:
https://splunkbase.splunk.com/app/2949/
It is based of the metadata
command mostly and this command tells you exactly what you need:
http://docs.splunk.com/Documentation/Splunk/6.6.0/SearchReference/Metadata
