Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to search which are the device not sending logs

$
0
0
Hi Team, How to search which are the host and Source not sending logs. the below metadata search shows only host. How can i add source . I need to column of source,Host,lasttime and duration. |metadata index!=network* index=win* index=lin* type=hosts | table host sourcetype lastTime | stats max(lastTime) as lastTime by host | eval diff = now()-lastTime | where diff > 3600|sort - diff | eval lastTime=strftime(lastTime,"%Y-%m-%d %H:%M:%S") |eval Duration=tostring(diff,"duration")|fields - diff Regards, Syed

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>