Splunk Search

fast way to query all index's to list index names and the time/date of the last event or update

jleppert
New Member

Is there a fast way to query all index's to list just the index name and the time/date of the last event or update?
My queries are taking entirely too long. I tried an 'eventcount' query which runs fast but it only provides sourcetype names and not the index names.

Tags (1)
0 Karma
1 Solution

javiergn
Super Champion

What about this?

| dbinspect index=*
| stats max(endEpoch) as _time by index

View solution in original post

0 Karma

javiergn
Super Champion

What about this?

| dbinspect index=*
| stats max(endEpoch) as _time by index
0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...