Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to query for a Week over Week count of hosts reporting to Splunk

$
0
0
Is there a better way to report the count of hosts reporting to Splunk week over week other than running the query using `index=*` I am not looking for the no of forwarders, I am looking distinct count of `host` value in all the indexes, |metadata type=hosts do not help as it cannot be used for week over week calculation index=* earliest=-2w@w latest=@w | bucket span=1d _time | stats count by _time host | eval marker=if (_time

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>