Splunk Search

Why is the metadata command showing the wrong firstTime?

david_halbeisen
New Member
| metadata type=sourcetypes index=*

My time range picker is set to today (Today is July 30, 2015). I analyzed my data and I know for certain that ALL of my sourcetypes have data prior to firstTime. Why is this field reporting wrong information? Actually I have data that is 4 years old for most of my sourcetypes, but the aforementioned search is giving me early July 2015 dates. Thank you for your assistance.

Tags (1)
0 Karma
1 Solution

sduff_splunk
Splunk Employee
Splunk Employee

The metadata command is not designed to honour the time picker. If you need to look at the metadata for a particular time range, you should use the metasearch command (http://docs.splunk.com/Documentation/Splunk/6.2.4/SearchReference/Metasearch)

| metasearch index=* | stats first(_time) as earliest_time, last(_time) as latest_time by sourcetype

Albiet, this is usually slower than the metadata command

View solution in original post

sduff_splunk
Splunk Employee
Splunk Employee

The metadata command is not designed to honour the time picker. If you need to look at the metadata for a particular time range, you should use the metasearch command (http://docs.splunk.com/Documentation/Splunk/6.2.4/SearchReference/Metasearch)

| metasearch index=* | stats first(_time) as earliest_time, last(_time) as latest_time by sourcetype

Albiet, this is usually slower than the metadata command

Gayathirik
Path Finder

Hi

Could you please assist to write a query to find out the newly added host for past 7 days? .

Thanks!!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...