Getting Data In

How to get index in the results with respective sourcetype?

PavanSeerapu
Explorer

 

index=_internal source=*metrics.log

| eval MB=round(kb/1024,2)

| search group="per_sourcetype_thruput"

| stats sum(MB) by series | eval sourcetype=lower(series)

| table index sourcetype "sum(MB)"

| append [| tstats latest(_time) as latest where index=* earliest=-24h by sourcetype |eval LastReceivedEventTime = strftime(latest,"%c") |table index, sourcetype LastReceivedEventTime | eval sourcetype=lower(sourcetype)]

| stats values(*) as * by sourcetype

| where LastReceivedEventTime != ""

 

 

Above query giving me sourtype, latest time stamp and sum(MB), but unable to get index, can someone please help

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @PavanSeerapu,

after a stats command, you have only the fields used in the stats, so you have to add the index to all your stats commands,

something like this:

index=_internal source=*metrics.log group="per_sourcetype_thruput"
| eval MB=round(kb/1024,2)
| stats sum(MB) values(index) AS index by series 
| eval sourcetype=lower(series)
| append [ 
   | tstats latest(_time) as latest where index=* earliest=-24h by sourcetype
   | eval LastReceivedEventTime = strftime(latest,"%c") 
   | table index sourcetype LastReceivedEventTime 
   | eval sourcetype=lower(sourcetype)
   ]
| stats values(*) as * by sourcetype
| where LastReceivedEventTime != ""

Ciao.

Giuseppe

0 Karma

Amick
Loves-to-Learn Lots

Add index to your subsearch "by" clause

index=_internal source=*metrics.log group="per_sourcetype_thruput"
| eval MB=round(kb/1024,2)
| stats sum(MB) by series | eval sourcetype=lower(series)
| table index sourcetype "sum(MB)"
| append [| tstats latest(_time) as latest where index=* earliest=-24h by index, sourcetype |eval LastReceivedEventTime = strftime(latest,"%c") |table index, sourcetype LastReceivedEventTime | eval sourcetype=lower(sourcetype)]
| stats values(*) as * by sourcetype
| where LastReceivedEventTime != ""
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...