Splunk Search

How to find out which source, source type and host are not getting data into Splunk?

Reddi694325
Path Finder

Hi All,

In my environment having a huge number of host, source and source types. From some of the host or source or source type, we are not getting data. Wanted to find which host or source or source type not sending data into Splunk and from what time onwards host, source, source type not sending data. Wanted to see in a table like below format

Host | Source | Source Type | Data not Coming In | Time(from what time onwards data is not coming )

0 Karma

lakshman239
Influencer
0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...