splunksplunk-querysplunk-sdk

Splunk query to get max indexed timestamp for a source type


I need Splunk query to get maximum indexed timestamp or latest indexed timestamp for a source type.

Please help as I am stucked here for quite long.

your help is highly appreciated.

thanks


Solution

  • This should do it.

    | tstats latest(_time) where index=* by sourcetype