Splunk search for List of sourcetypes being sent by each Forwarder

Copy
index=_internal | where host!=splunk_server | stats values(series) as Sourcetypes by host | rename host as Host
This Splunk search will provide a list of all sourcetypes that are being reported by each host sending data to Splunk.
0 comments

Category:

General Splunk


Tags:

Admin general internal

Search Commands:

Sign in or Register to submit a comment