Getting Data In

Query to list All indexes and sourcetypes of All Apps present in an instance

rizshez
Engager

I need help to find a query that can list every source types and indexes of each and every app present in the search head or an instance. Is it possible to get the results using SPL?

Labels (5)
0 Karma

splunkcol
Builder

Hi, I'm also new, I don't know if what I'm going to answer is helpful, I'll still try


index=* |stats count by index sourcetype app |sort -count

rizshez
Engager

What I am trying to achieve is get list of all sourcetypes and indexes of TA. By that I mean what sourcetype and indexes is that specific TA is using.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...