Thanks for the query, i developed it to be something usable.... | rest splunk_server_group=dmc_group_indexer splunk_server_group="*" /services/data/indexes
| stats max(maxTime) AS latestEvent BY title
| eval elapsedTime = now() - strptime(latestEvent,"%Y-%m-%dT%H:%M:%S%z"), daysSince = ceiling(elapsedTime / 86400)
| eval daysSinceLastEvent = case(daysSince<0, -1, daysSince=0, 0, daysSince>0,daysSince)
| eval indexStatus = case(daysSinceLastEvent>730, "Nothing Since 2 years",
daysSinceLastEvent<730 AND daysSinceLastEvent>365, "Nothing Since last year",
daysSinceLastEvent<365 AND daysSinceLastEvent>0, "used in last year",
daysSinceLastEvent=0, "Till today",
daysSinceLastEvent<0, "bad future timestamp")
| fields title latestEvent daysSinceLastEvent indexStatus
... View more