Splunk Search

Export list of files being indexed into Splunk

efelder0
Communicator

Is there a way (Splunk feature or search cmd) to export a list of files that were indexed and then create a report?

Tags (1)
1 Solution

Ayn
Legend

You can use metadata and grab the sources from there:

| metadata type=sources

View solution in original post

Ayn
Legend

You can use metadata and grab the sources from there:

| metadata type=sources

Ayn
Legend

... | eval recentTime=strftime(recentTime,"%+")

0 Karma

efelder0
Communicator

Yes, that works. Here is my search string:
| metadata type=sources index=* | sort +source | table recentTime source

However, 'recentTime' is in this format: 1335274216
best way to convert it to MM/DD/YY HH:MM:SS ??

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...