Hello,
we would like to compare sources we ask to index and current state in Splunk (compare inputs.conf and current license usage) to see if we have missing data.
I found this https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-a-list-of-data-inputs-using-the-REST-A... to list all inputs however I would like also to get active associated target hosts (clients) found in serverclasses.
Thanks.
Please give us more detail about your use case. Finding missing data can be a challenge because Splunk can't tell you what it doesn't have.
What exactly are you looking for regarding "active associated target hosts (clients) found in serverclasses"?
Hi Rich,
for instance we have sources defined in inputs.conf, we can also see them in manager / data inputs / forwarded inputs / files & directory then we want to see if they are effectively indexed.
Thanks for your help!
I'm not sure there's a good solution for this problem for a number of reasons.
Check out the TrackMe app (https://splunkbase.splunk.com/app/4621), which may address your problem.