I need to get the list of Sourcetypes by Index in a Dashboard.
I got this search from Splunk forums which gives the list, but the index name is listed for all sourcetypes. I need to group by Index. Also, when I save this as a dashboard panel, it never shows any data.
Report works fine. Any other way/search to get the data from _internal indexes?
| eventcount summarize=false index=* index=_* | dedup index | fields index | map maxsearches=100 search="|metadata type=sourcetypes index=\"$index$\" | eval index=\"$index$\"" | fields index sourcetype
| metadata type=sourcetypes index=* | stats values(sourcetypes) by index
just learned this week that
tstats is the perfect command for this, because it is super fast. So take this example:
| tstats count WHERE index=* OR sourcetype=* by index,sourcetype | stats values(sourcetype) AS sourcetypes by index
Hope this helps ...