Anyone have a quick search on how to measure how long it's taking for data to go from Universal forwarder to be searchable?
Like this:
index=* | eval lagSeconds=_indextime - _time | timechart span=30m avg(lagSeconds) BY host
Better yet, install a DMC and get a full summary there.
Like this:
index=* | eval lagSeconds=_indextime - _time | timechart span=30m avg(lagSeconds) BY host
Better yet, install a DMC and get a full summary there.