I want a table that shows my hosts, sources, source types, and indexes with some data feeds. How do I approach that?
i was thinking to do
source=" source1" , host = " " sourcetype "sourcetype11 " , index= "index1"
source="source2" , host = " " sourcetype "sourcetype22 " , index= "index2"
|table source, host, sourcetype, index
The above is not working and not giving me results. Is there an easy way to solve this problem? I'm using Splunk Enterprise search and reporting. Thanks!
Try | tstats count by source, host, sourcetype, index | table source host sourcetype index
.
Try | tstats count by source, host, sourcetype, index | table source host sourcetype index
.
Thank you so much!!!