Hi,
Plugin for Splunk allows to check indexes updates :
| Service Alias | Service Template | Service Description | Default |
|---|---|---|---|
| Index-Update | App-Monitoring-Splunk-Index-Update-Api | Check indexes last update time | X |
or in french
| Alias | Modèle de service | Description | Défaut |
|---|---|---|---|
| Index-Update | App-Monitoring-Splunk-Index-Update-Api | Contrôle l'heure à laquelle un index a été mis à jour pour la dernière fois | X |
BUT : the “last update time” doesn’t return the latest in the meaning “the closest from now”, but instead the older record in the index. So it’s no use to check if indexes are updated regularly.
→ it would be nice to upgrade the plugin and add possibility to get the real “latest” record time (identified as “min time” in Splunk).
Regards,




