Getting Data In

Splunk server uptime - missing Splunk server details

Hi all,

I am running the below query, I get responses from some of my Splunk servers but not all ?

| rest /services/server/info | eval LastStartupTime=strftime(startuptime, "%Y/%m/%d %H:%M:%S")
| eval timenow=now()
| eval daysup = round((timenow - startup
time) / 86400,0)
| eval Uptime = tostring(daysup) + " Days"
| table splunk_server LastStartupTime Uptime

Is there anything I am missing on the servers that are not reporting back ?


Please, check this splunk answers, maybe it fits your purposes:

The rest command is only sent to indexers so only those servers will respond. You will not get any data about search heads and other non-indexer instances.

cheers for the info richgalloway

