Splunk search for Hosts added to Splunk each month
Copy
| tstats dc(host) as Host by date_month | rename date_month as Month | eval Month=upper(substr(Month,1,1)).lower(substr(Month,2))
This Splunk search will provide a count of the number of hosts that have reported data to Splunk within the timeframe selected. The search separates out the count of hosts by month. Because the search utilizes the tstats command it can be used to search over a large timespan and will run very quickly.