Show all Indexes and Sourcetypes via REST

The following Splunk query uses REST to display non internal indexes associated with sourcetypes. It is my understanding that this is all time (such is the way of REST searches)

| rest /services/data/inputs/all
| search index!=_*
| stats values(sourcetype) by index
Share This:

Leave A Comment?