Deployment Architecture

way to identify data not indexed

mraudaschl
Loves-to-Learn

hi all,
recently, following an update to Splunk 6.4.3 we are having trouble finding data with searches that worked before. We suspect it is related to re-indexing during the update. Is there a way to identify if there is data which still needs to be indexed?

0 Karma

inventsekar
Super Champion

this search will list out the hosts and their last time these host sent any data to splunk(sort lastTime).

| metadata type=hosts 
  | fields host firstTime lastTime totalCount
  | fieldformat firstTime=strftime(firstTime,"%x %X")
  | fieldformat lastTime=strftime(lastTime,"%x %X")
  | sort lastTime
>>> Happy Splunking !
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>