Splunk search for Values of host, source and sourcetype per index

Copy
| tstats count values(host) as host, values(source) as source, values(sourcetype) as sourcetype by index
This Splunk search utilizes the tstats command to output the values of host, source and sourcetype that are reporting to each non-internal index.
0 comments

Category:

General Splunk


Tags:

Admin general

Search Commands:

Sign in or Register to submit a comment