Splunk Search
Highlighted

How to search a list of sourcetypes by index and save it as a dashboard panel?

Communicator

I need to get the list of Sourcetypes by Index in a Dashboard.

I got this search from Splunk forums which gives the list, but the index name is listed for all sourcetypes. I need to group by Index. Also, when I save this as a dashboard panel, it never shows any data.

Report works fine. Any other way/search to get the data from _internal indexes?

Search:

| eventcount summarize=false index=* index=_* | dedup index | fields index 
 | map maxsearches=100 search="|metadata type=sourcetypes index=\"$index$\" | eval index=\"$index$\""
 | fields index sourcetype

Thanks.

0 Karma
Highlighted

Re: How to search a list of sourcetypes by index and save it as a dashboard panel?

Esteemed Legend

Try this:

| metadata type=sourcetypes index=*  | stats values(sourcetypes) by index
0 Karma
Highlighted

Re: How to search a list of sourcetypes by index and save it as a dashboard panel?

Communicator

Thanks for the reply @woodcock
Does not return any results for me.

0 Karma
Highlighted

Re: How to search a list of sourcetypes by index and save it as a dashboard panel?

SplunkTrust
SplunkTrust

Hi athorat,

just learned this week that tstats is the perfect command for this, because it is super fast. So take this example:

| tstats count WHERE index=* OR sourcetype=* by index,sourcetype | stats values(sourcetype) AS sourcetypes by index

Hope this helps ...

cheers, MuS

View solution in original post

Highlighted

Re: How to search a list of sourcetypes by index and save it as a dashboard panel?

Engager

Maybe the cleanest (fastest) way?

|tstats values(sourcetype) by index