Splunk Search

To which index does the sourcetype belong?

Neonbeeflash3
New Member

Greetings,

I have been creating a search that collects all the sourcetypes that have not collected any information during the last 4 hours (Which I was able to accomplish). The thing is that I need to know which indexes these sourcetypes belong to in this same search. Any idea?

This is the search:

| metadata type=sourcetypes index=*
| search sourcetype=*
| where lastTime<now()-14400
| eval ageInSeconds = (now()- firstTime)
| search ageInSeconds > 86400
| convert ctime(lastTime) ctime(recentTime) ctime(firstTime)
| table sourcetype, lastTime

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Sourcetypes do not "belong" to indexes.  There is no association between an index and a sourcetype other than one happened to found within the other.

If a sourcetype was not found during a particular period then it doesn't "belong" to any index in that period.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Neonbeeflash3
New Member

I'm sorry if I explained wrong, each of the sourcetypes that I can filter with this search are related to an index. What I would like to see is which index they are related to. For example, one of the sourcetypes I get is called "hello" (example names) and this sourcetype is related to an index called "goodbye". What I would like to see in this search is the index to which "hello" is related.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Any relationship between sourcetype and indexer is of your own making and so must be the solution.

Perhaps you can build a lookup table of sourcetypes and expected index(es).

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...