Hi,
I am trying to get the information how many datasources and endpoints we have Integrated in to splunk.How can we get this information can anyone pls provide me a query to find this ..
@gcusello @richgalloway
Please correct me if I'm mistaken, but the source is where the data begins, while the endpoint acts as the destination or host where the data is either stored or received.
Computer terms can be confusing since they often have several meanings.
"source" is where the data comes from. In Splunk metadata, the source is the name of the file from which the data originated. "source" can also refer to the originating server or app.
"endpoint" usually refers to a user workstation, but a specific REST command is also an endpoint.
Hi @AL3Z ,
as I said, with my search you have the list of all data flows (sourcetypes) for each endpoint (host).
Ciao.
Giuseppe
There's also this method to get a list of data sources
| tstats count where index=* by source
Hi @AL3Z ,
you could use one of these searches:
list of endpoints:
| tstats count WHERE index=* BY host
list of data sources:
| tstats count WHERE index=* BY sourcetype
you can also gave both the information in pone search:
| tstats values(sourcetype) AS sourcetype count WHERE index=* BY host
Ciao.
Giuseppe