Can any one help me with SPL to extract report of recent log sources reporting with time and the time difference from current time.
Thanks in Advance!
This is a very hard problem, however the metawoot app does the best job of providing the sort of reports you want: https://splunkbase.splunk.com/app/2949/
Silly name, excellent app 🙂
All the best.