Getting Data In

sourcetype reporting interval?

Path Finder

Anybody have a query to show sourcetype reporting intervals (how often a ST sends data). I cant download or install any apps, so I need to use spl. Timechart maybe? Anybody have a dashboard for this?

Gracias

0 Karma

Builder

Hi,
I use this to monitor the health of my sourcetypes:
| tstats count where index=* by _time, sourcetype,index span=1h | stats sparkline(sum(count)) as fingerprint, sum(count) as count by sourcetype,index

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!