I've been using tstats for most of the use cases that metasearch covers, and so I'm interested in what metasearch can do that tstats can't. From my reading of the documentation, it seems that metasearch...
I can run |metasearch ((index=IN1 sourcetype=S1) OR (index=IN2 sourcetype=S2)) and it works — no issues.
I can create a macro, say mysrc with definition (index=IN1 sourcetype=S1) OR (index=I...
Hi,
I' cant end my search using metasearch when I need to find in index something with space betwen like "Microsoft Update". There is no problem to find there one word aplikaction like b...
I was wondering whether Splunk supports earliest and latest date in Metadata, metasearch, and tstats command?
I tried to check all the sites but couldn't find it.
How to use multiple metadata O...
I am trying to do a time chart of available indexes in my environment , I already tried below query with no luck
| tstats count where index=* by index _time
but i want results in the same form...
Hello,
please can someone assist with creating syntax to
1. know the numbers of desktop, laptops, servers and network devices that I have onboarded into Splunk cloud?
2. Create alert if a...
Hey, We have some 1500 servers where splunk forwarders installed. we need the path to find location of data or logs coming from these servers. Is there a simple way to do that?
Hello,
I'd like to display all sourcetypes available for each index in my environment. Unfortunately, metadata type=sourcetypes doesn't preserve the index name, and I want to be able to run it on...
Hi team. I'm looking for a query/solution that will alert me when a log source is no longer sending logs. For example, I have an index called "linux_prod" which is populated when linux hosts fortheir...
Hello, We have been using this query to list out hosts that are not sending logs since past 24h. It has been working well and for some unknown reason it has now suddenly stopped working.&...