Splunk Search

How to find the missing source files that are not indexed

deepthi5
Path Finder

Hi team,

I have 10 different hosts that are sending data to the SPLUNK every day
they send some csv files daily C:\SPLUNKCEBU\xxxx.csv, etc

Now i want to find out for a particular day if the data from all the files from all hosts are indexed or not (if not indexed then i can check my host if the files are present are not)

Thanks
deepthi

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

you can most likely use a simple search to validate your inputs with help of the source attribute, e.g.

your_search | timechart span=1d distinct_count(source) values(source)

/k

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...