Splunk Search

To which index does the sourcetype belong?

Neonbeeflash3
New Member

Greetings,

I have been creating a search that collects all the sourcetypes that have not collected any information during the last 4 hours (Which I was able to accomplish). The thing is that I need to know which indexes these sourcetypes belong to in this same search. Any idea?

This is the search:

| metadata type=sourcetypes index=*
| search sourcetype=*
| where lastTime<now()-14400
| eval ageInSeconds = (now()- firstTime)
| search ageInSeconds > 86400
| convert ctime(lastTime) ctime(recentTime) ctime(firstTime)
| table sourcetype, lastTime

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Sourcetypes do not "belong" to indexes.  There is no association between an index and a sourcetype other than one happened to found within the other.

If a sourcetype was not found during a particular period then it doesn't "belong" to any index in that period.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Neonbeeflash3
New Member

I'm sorry if I explained wrong, each of the sourcetypes that I can filter with this search are related to an index. What I would like to see is which index they are related to. For example, one of the sourcetypes I get is called "hello" (example names) and this sourcetype is related to an index called "goodbye". What I would like to see in this search is the index to which "hello" is related.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Any relationship between sourcetype and indexer is of your own making and so must be the solution.

Perhaps you can build a lookup table of sourcetypes and expected index(es).

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...