Getting Data In

Splunk server uptime - missing Splunk server details

New Member

Hi all,

I am running the below query, I get responses from some of my Splunk servers but not all ?

| rest /services/server/info | eval LastStartupTime=strftime(startuptime, "%Y/%m/%d %H:%M:%S")
| eval timenow=now()
| eval daysup = round((timenow - startup
time) / 86400,0)
| eval Uptime = tostring(daysup) + " Days"
| table splunk_server LastStartupTime Uptime

Is there anything I am missing on the servers that are not reporting back ?


Tags (2)
0 Karma


Please, check this splunk answers, maybe it fits your purposes:

0 Karma


The rest command is only sent to indexers so only those servers will respond. You will not get any data about search heads and other non-indexer instances.

If this reply helps you, an upvote would be appreciated.
0 Karma

New Member

cheers for the info richgalloway

0 Karma