Is there a fast way to search all indexes to list just the index name and the time/date of the last event or update?
My searches are taking entirely too long. I tried an 'eventcount' search which runs fast, but it only provides sourcetype names and not the index names.
You should be able to use a rest command to get the results:
|rest /services/data/indexes | table title
Give a shot hope fully it solves your query
index=* | eval latest=now()|table index latest converttime |eval converttime=strftime(latest,"%m/%d/%y %H:%M:%S") |dedup index latest
That looks to work but it runs too slow. Any query I run starting with Index=* runs too slow
I was hoping something faster using dbinspect or tstats
try this
| tstats latest(_time) as latest by index |eval converttime=strftime(latest,"%m/%d/%y %H:%M:%S")|fields index converttime
This should get you what you need:
index=*
| stats latest(_time) as latestTime by index
| eval latestTime=strftime(latestTime,"%x %X")
That looks to work but it runs too slow. Any query I run starting with Index=* runs too slow
This might be faster:
| eventcount summarize=false index=* index=_*
| dedup index | fields index | map maxsearches=100 search="|metadata type=sourcetypes index=\"$index$\"
| eval index=\"$index$\"" | eval latestTime=strftime(lastTime,"%x %X") | table latestTime index | stats max(latestTime) by index
Error in 'map': Did not find value for required attribute 'index'.
You should be able to use a rest command to get the results:
|rest /services/data/indexes | table title
|rest /services/data/indexes | table title updated
Of course, it does. Your indexes reside on multiple indexers with different update times. If you don't want duplicates you have a couple of options.
|rest /services/data/indexes | dedup title | table title updated
|rest /services/data/indexes | stats first(updated) by title
That runs quick, thx!
that doesn't give the time/date of the last event
This does:
|rest /services/data/indexes | table title updated
Does it have to be a query? The Settings->Indexes screen shows the information you seek.