Splunk Search
Highlighted

Splunk Hosts metadata correlation with index

Path Finder

Im using a metadata type=hosts query to output hosts that have not logged data using recenttime
However i dont see the index name being output by this..is there anyway to correlate the host to its index in a query that starts with |metadata type=hosts ?
thanks!

Tags (2)
Highlighted

Re: Splunk Hosts metadata correlation with index

SplunkTrust
SplunkTrust

You could use this to emulate metadata:

| tstats latest(_time) latest(_indextime) count where index=* by host index
Highlighted

Re: Splunk Hosts metadata correlation with index

Path Finder

Hmmm...this throws error expecting a namespace ...tsidxstats error...missing "FROM" keyword to specify namespace
does this work against indexes ? above error suggests it runs only against tsidxstats of tscollect

0 Karma
Highlighted

Re: Splunk Hosts metadata correlation with index

SplunkTrust
SplunkTrust

This runs against indexes... on Splunk 6. Are you still on version 5?

0 Karma
Highlighted

Re: Splunk Hosts metadata correlation with index

Path Finder

yes on splunk 5.0.4 unfortunately...is there some way we can do the same ? i just need to find the latest time each host has logged using metadata but also output what index it belongs to ...

0 Karma
Highlighted

Re: Splunk Hosts metadata correlation with index

SplunkTrust
SplunkTrust

Anything tstats can do with indexes can be done with stats:

index=* | stats latest(_time) latest(_indextime) count by host index

However, that may be slow, very slow, or glacial. You can of course speed things up by running this query regularly over a short timerange and storing the data in a lookup: http://blogs.splunk.com/2011/01/11/maintaining-state-of-the-union/

0 Karma
Highlighted

Re: Splunk Hosts metadata correlation with index

Legend

I've filed an ER for metasearch to output _indextime in results. With that, you could quickly grab these stats.

0 Karma
Highlighted

Re: Splunk Hosts metadata correlation with index

SplunkTrust
SplunkTrust

Yeah, metasearch with _indextime should be about twice as fast as regular stats... if your forwarders basically send current data then you could get along with using _time as a workaround.

0 Karma
Highlighted

Re: Splunk Hosts metadata correlation with index

Path Finder

Thanks ... unless i misundertood something recenttime is indextine for metaseach on hosts ...but metasearch do not output the index names on which they run...i need to be able to read the results to act on it and it needs to have the index name...

0 Karma
Highlighted

Re: Splunk Hosts metadata correlation with index

SplunkTrust
SplunkTrust

metasearch does output the index.

0 Karma