Splunk search for Hosts added to Splunk each month

Copy
| tstats dc(host) as Host by date_month | rename date_month as Month | eval Month=upper(substr(Month,1,1)).lower(substr(Month,2))
This Splunk search will provide a count of the number of hosts that have reported data to Splunk within the timeframe selected. The search separates out the count of hosts by month. Because the search utilizes the tstats command it can be used to search over a large timespan and will run very quickly.
0 comments

Category:

General Splunk


Tags:

tstats Admin general

Search Commands:

Sign in or Register to submit a comment