Index=X sourcetype=Y cribl_pipe=Z when I ran for 1week and 24hrs it showed index , sourcetype field with 100%
Index=X sourcetype=Y cribl_pipe=Z when I ran for 2weeks and 1month index , sourcetype field is not showing up 100% can some please suggest on this.
I'm searching for single index and single sourcetype but for 1week it's showing 100% field value, for 2 weeks it's not showing 100% what can be the issue ?
How can I identify raw events which are not indexed source tcp:9997 port