Hi Team,
Is there any way to find out what are the sourcetypes completely reporting in Splunk for both index and as well as for non-internal index for last 30 days so if we have any query to pull out those information it would be really helpful.
Hi @anandhalagaras1,
You can list all sourcetypes using below query;
| metadata type=sourcetypes index=_* index=*
Hi @anandhalagaras1,
You can list all sourcetypes using below query;
| metadata type=sourcetypes index=_* index=*