Splunk Search

Why are there no time stamp in Earliest and Latest Events for main index

Masa
Splunk Employee
Splunk Employee

I have two search heads, four indexers, and several forwarders.
When I go to Manager -> Indexes, my main index shows N/A in both Earliest event and Latest event. But, I can search events in main index.

Why can I see the earliest and latest time stamp for main index in the Manager?

I would like to see the earliest timestamp and latest timestamp of the main index database for each search peer(indexer).

I can do the following search for All Time. But it takes so long time to finish the search.


index=main splunk_server=myIndexer01
| stats min(_time) AS EarliestTime max(_time) AS LatestTime
| convert ctime(*Time)

Is there any better way to check the earliest timestamp and latest timestamp?

Tags (1)
1 Solution

zliu
Splunk Employee
Splunk Employee

If it is a dedicated search head, user won't see any time range information at Manager --> Indexes, since there is no indexing on the dedicated search head.

In order to see time range information on the search head, please do below search:

| metadata type=hosts index=_internal splunk_server=full_servername | convert ctime(*Time)

Make sure the splunk_server name contain the full server name with domain.

View solution in original post

zliu
Splunk Employee
Splunk Employee

If it is a dedicated search head, user won't see any time range information at Manager --> Indexes, since there is no indexing on the dedicated search head.

In order to see time range information on the search head, please do below search:

| metadata type=hosts index=_internal splunk_server=full_servername | convert ctime(*Time)

Make sure the splunk_server name contain the full server name with domain.

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...