Hi All,
In my environment having a huge number of host, source and source types. From some of the host or source or source type, we are not getting data. Wanted to find which host or source or source type not sending data into Splunk and from what time onwards host, source, source type not sending data. Wanted to see in a table like below format
Host | Source | Source Type | Data not Coming In | Time(from what time onwards data is not coming )
You could look at some the the below answers and create one that suits your need. You can use metadata or metasearch, which is widely used for a resonable sized deployments.
https://answers.splunk.com/answers/3181/how-do-i-alert-when-a-host-stops-sending-data.html
https://answers.splunk.com/answers/435074/is-there-a-dashboard-to-monitor-when-event-data-is.html
https://answers.splunk.com/answers/89020/query-for-host-not-sending-sourcetype.html