Splunk Search

index data

Siddharthnegi
Contributor

Hello , How can I know the start time and the latest time  coming of data of all index .
meaning that when was the first time data came in that index and when is the latest time data have came in that index.

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Do you really want to know the times in the entire index?  If so, tstats is usually the way to go.

| tstats min(_time) as start max(_time) as end where index=myindex
| fieldformat start = strftime(start, "%F %T")
| fieldformat end = strftime(end, "%F %T")

Something like that.

Siddharthnegi
Contributor

Thank You for your reply , but I want this information for all indexes  at once with their respective names is that possible?

0 Karma

yuanliu
SplunkTrust
SplunkTrust

This is where you need to be extra diligent in problem statement.  Yes, it is doable but volunteers are not mind readers.

| tstats min(_time) as start max(_time) as end where index=* by index
| fieldformat start = strftime(start, "%F %T")
| fieldformat end = strftime(end, "%F %T")

 

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...