Splunk Search
Highlighted

How to find out which source, source type and host are not getting data into Splunk?

Engager

Hi All,

In my environment having a huge number of host, source and source types. From some of the host or source or source type, we are not getting data. Wanted to find which host or source or source type not sending data into Splunk and from what time onwards host, source, source type not sending data. Wanted to see in a table like below format

Host | Source | Source Type | Data not Coming In | Time(from what time onwards data is not coming )

0 Karma
Highlighted

Re: How to find out which source, source type and host are not getting data into Splunk?

SplunkTrust
SplunkTrust
0 Karma