Is there a fast way to query all index's to list just the index name and the time/date of the last event or update?
My queries are taking entirely too long. I tried an 'eventcount' query which runs fast but it only provides sourcetype names and not the index names.
What about this?
| dbinspect index=*
| stats max(endEpoch) as _time by index
What about this?
| dbinspect index=*
| stats max(endEpoch) as _time by index