Knowledge Management

How can I search for the sourcetype and their key value pair setup (Name/Value) for all indexes?

NanSplk01
Path Finder

I want to create a list per index of all the sourcetypes under it and the key value pairs set in the sourcetypes and I want to export this to a cvs file.

index=*

Name                                                                    Value

CHARSET                                                            UTF-8

MAX_TIMESTAMP_LOOKAHEAD              23

etc:

Labels (2)
Tags (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

And what's the use case? Because depending on your architecture you might not get what you want. Remember that there are search-time settings and index-time settings. And some index-time settings might even be configured in a place you don't have access to (if you have a HF in some external site, for example). Also remember that props can be defined on a per-source or per-host basis, not necessarily only per-sourcetype. So the overall picture might be much more complicated.

0 Karma

somesoni2
SplunkTrust
SplunkTrust

If you just want all the attributes setup for all sourcetypes, give this a try

| rest /services/configs/conf-props | table title * | regex title="^[A-z0-9]" | untable title attribute value | rename title as sourcetype

If you want index name as well, try this less efficient option

| rest /services/configs/conf-props | table title * | regex title="^[A-z0-9]" | untable title attribute value | rename title as sourcetype | join type=left sourcetype [ |tstats count WHERE index=* by index sourcetype | table index sourcetype  ]
0 Karma

NanSplk01
Path Finder

The 1st suggestion works, but as you indicated there were no indexes.  I ran the 2nd and only received one or two indexes, the others were blank.  I will keep working on the first search and see what I might come up with.  Thank you for the start.

Tags (1)
0 Karma

somesoni2
SplunkTrust
SplunkTrust

In the 2nd search, the "tstats" command runs based of the selected time range, so if you want to see info for more index/sourcetypes, select a timerange for which that index/sourcetype will have data.

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...