Splunk Search

How to find out which source, source type and host are not getting data into Splunk?

Reddi694325
Path Finder

Hi All,

In my environment having a huge number of host, source and source types. From some of the host or source or source type, we are not getting data. Wanted to find which host or source or source type not sending data into Splunk and from what time onwards host, source, source type not sending data. Wanted to see in a table like below format

Host | Source | Source Type | Data not Coming In | Time(from what time onwards data is not coming )

0 Karma

lakshman239
Influencer
0 Karma
Get Updates on the Splunk Community!

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...

Splunk AppDynamics Agents Webinar Series

Mark your calendars! On June 24th at 12PM PST, we’re going live with the second session of our Splunk ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2025 SplunkTrust is officially open! If you ...