I have a search that starts off with
| metadata type=hosts ....
The problem is that the results are pulling back a host that is not sending logs or should be sending logs. A search for the host in Splunk turns up nothing.
So my question is why it's showing up in metadata if no logs are being collected (or have ever been collected) from that host?
Hi reswob4,
there could be multiple reasons for this:
delete
command for this host which makes events not searchable but they are still in your index and therefore in the metadata.Hope this helps ...
cheers, MuS
Hi reswob4,
there could be multiple reasons for this:
delete
command for this host which makes events not searchable but they are still in your index and therefore in the metadata.Hope this helps ...
cheers, MuS
Thanks.
I'm going to mark this as answered, but if anyone else has suggestions, that would be much appreciated.