You need another
s for starters but you cannot do what you are trying to do with the command that you are trying to use. See what I mean with these:
| metadata type=sources index=* OR index=_* | metadata type=sourcetypes index=* OR index=_*
But you can do it with
tstats like this:
| tstats values(source) WHERE index=* OR index=_* BY sourcetype
Hi kteng2024, You might find
tstats would work better here. i.e.
| tstats count where sourcetype=YOUR_SOURCETYPE by source
This will give you a list sources for that sourcetype. It should be fairly quick to run over large timeframes.
Please let me know if this answers your question! 😄