Splunk Search

How to find the missing source files that are not indexed

deepthi5
Path Finder

Hi team,

I have 10 different hosts that are sending data to the SPLUNK every day
they send some csv files daily C:\SPLUNKCEBU\xxxx.csv, etc

Now i want to find out for a particular day if the data from all the files from all hosts are indexed or not (if not indexed then i can check my host if the files are present are not)

Thanks
deepthi

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

you can most likely use a simple search to validate your inputs with help of the source attribute, e.g.

your_search | timechart span=1d distinct_count(source) values(source)

/k

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...