I am attempting to determine the earliest event in a particular index by executing the following search over All Time (as instructed by the Metadata command). I am running Splunk Enterprise 7.0.2:
| metadata type=hosts index=vpn
Error in 'metadata': No 'host' key found in results. Cannot merge metadata.
If I choose different time periods, some of them work (previous 30 days, Year to Date) but some do not (previous year). Anyone see this before?
@scottprigge, can you try the tstats command and see how it behaves:
| tstats count earliest(_time) as EarliestTime latest(_time) as LatestTime where index="vpn" by host | fieldformat EarliestTime=strftime(EarliestTime,"%Y-%m-%d %H:%M:%S") | fieldformat LatestTime=strftime(LatestTime,"%Y-%m-%d %H:%M:%S")