I would like to monitor a specific index and get the following information:
source - name
oldest searchable event by source.
I understand the basics of dbinspect that it will display the startEpoch values and sort it for the earliest value and I can figure out the oldest event using this field and sourceCount only, however I need to identify the source "name" so I can pair the 2: source name and oldest searchable event
OR if there is another command I can use instead of dbinspect that will provide the needed information. Doing stats command in this use case will not work as I will be looking for events that are 1 year old and I favor the dbinspect search time.
Thanks and regards.
metadata comes to mind. Try
| metadata type=sources index=_internal
This is provided that the time is of concern. Or do you need to retrieve that very record?
Very thankful to this community. I tried both and the metadata is the information that I was looking for. I also tried the tstat command recommendations but when I ran for all time, it only found events that are 3 months old.
Thank you both!
Have you tried the tstats command? It's very fast and can get the information you want.
| tstats earliest(_time) as oldest where index=foo by source | fieldformat oldest=strftime(oldest,"%Y-%m-%d %H:%M:%S")