Splunk Search

To which index does the sourcetype belong?

Neonbeeflash3
New Member

Greetings,

I have been creating a search that collects all the sourcetypes that have not collected any information during the last 4 hours (Which I was able to accomplish). The thing is that I need to know which indexes these sourcetypes belong to in this same search. Any idea?

This is the search:

| metadata type=sourcetypes index=*
| search sourcetype=*
| where lastTime<now()-14400
| eval ageInSeconds = (now()- firstTime)
| search ageInSeconds > 86400
| convert ctime(lastTime) ctime(recentTime) ctime(firstTime)
| table sourcetype, lastTime

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Sourcetypes do not "belong" to indexes.  There is no association between an index and a sourcetype other than one happened to found within the other.

If a sourcetype was not found during a particular period then it doesn't "belong" to any index in that period.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Neonbeeflash3
New Member

I'm sorry if I explained wrong, each of the sourcetypes that I can filter with this search are related to an index. What I would like to see is which index they are related to. For example, one of the sourcetypes I get is called "hello" (example names) and this sourcetype is related to an index called "goodbye". What I would like to see in this search is the index to which "hello" is related.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Any relationship between sourcetype and indexer is of your own making and so must be the solution.

Perhaps you can build a lookup table of sourcetypes and expected index(es).

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...