Anshu
Anshu

Reputation: 69

Splunk query to get max indexed timestamp for a source type

I need Splunk query to get maximum indexed timestamp or latest indexed timestamp for a source type.

Please help as I am stucked here for quite long.

your help is highly appreciated.

thanks

Upvotes: 1

Views: 1072

Answers (1)

RichG
RichG

Reputation: 9916

This should do it.

| tstats latest(_time) where index=* by sourcetype

Upvotes: 2

Related Questions