Knowledge Management

Overview of events and feeds coming in

ecanmaster
Explorer

Is there a quick way on getting a list of all events coming in and all feeds coming in?

Would it also be possible to see which feeds are being used for the data models?
And also getting a list of feeds that are not being used in searches?

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

There are apps for this kind of thing on splunkbase. You can start with this:

index=* | stats values(tag) BY sourcetype

The tags will indicate which datamodels each sourcetype goes into.

View solution in original post

0 Karma

woodcock
Esteemed Legend

There are apps for this kind of thing on splunkbase. You can start with this:

index=* | stats values(tag) BY sourcetype

The tags will indicate which datamodels each sourcetype goes into.

0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...