Splunk Enterprise Security

Is there a way to efficiently list all fields by Sourcetype and field?

tadecleid
New Member

I found a similar post that did not quite fit the bill of what I am trying to do.

I want to be able to create a link graph that shows a logical flow of all of our data from index>sourcetype>fields.

Issues I am running into:
| fieldsummary does not work with metadata and thus does not include the index or sourcetype.

|tstats search is only able to show index and sourcetype.

I figure there is a base search I need to set up to pull the initial sourcetypes to run fieldsummaries on, but I'm not sure how to string these techniques together or if something like this is even feasible without leaving a very heavy burden on the cluster.

I would like to make this a report that updates a lookup weekly so that the dashboard is referencing the lookup instead of running this search.

Thanks in advance for your time!

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...