Thank you, Can confirm that this works as expected. I was also looking for a way to see all of the splunk instances: Run from the DMC: | rest splunk_server=* /services/server/info | eval LastStartupTime=strftime(startup_time, "%Y/%m/%d %H:%M:%S")
| eval timenow=now()
| eval daysup = round((timenow - startup_time) / 86400,0)
| eval Uptime = tostring(daysup) + " Days"
| table splunk_server LastStartupTime Uptime
... View more
I agree with these statements. With all of the existing answers it is very hard to find nifty search queries as they are lost in a sea of white space. I just went back to answers from something I was looking at last week. It took a bit of digging to find the query that was provided down in the comments section. Would have been nice if all the existing data was either left untouched on the old system or put "code" tags around the queries so they stand out.
... View more