<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dashboard with status of a host in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Dashboard-with-status-of-a-host/m-p/88211#M18311</link>
    <description>&lt;P&gt;awesome.. thanks for the reply.. Will work witht he deployment monitor and the query you have provided. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Mar 2012 22:23:16 GMT</pubDate>
    <dc:creator>rajbahak</dc:creator>
    <dc:date>2012-03-08T22:23:16Z</dc:date>
    <item>
      <title>Dashboard with status of a host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Dashboard-with-status-of-a-host/m-p/88209#M18309</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Is it possible to create a dashbaord that will show the status (online/offline) of the hosts that send their data to be indexed by Splunk? &lt;/P&gt;

&lt;P&gt;If so please advise how can it be done.&lt;/P&gt;

&lt;P&gt;Thanks a ton&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2012 19:53:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Dashboard-with-status-of-a-host/m-p/88209#M18309</guid>
      <dc:creator>rajbahak</dc:creator>
      <dc:date>2012-03-08T19:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard with status of a host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Dashboard-with-status-of-a-host/m-p/88210#M18310</link>
      <description>&lt;P&gt;If you turn on the Splunk Deployment Monitor app, you will get a number of dashboards and statistics, including some information about the forwarders.  Or, you can try this search (which I lifted from one of the Deployment Monitor dashboards)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="_internal" source="*metrics.log" group=tcpin_connections | eval sourceHost=if(isnull(hostname), sourceHost,hostname) | eval connectionType=case(fwdType=="uf","Universal Forwarder", fwdType=="lwf", "Light Weight Forwarder",fwdType=="full", "Splunk Indexer", connectionType=="cooked" or connectionType=="cookedSSL","Splunk Forwarder", connectionType=="raw" or connectionType=="rawSSL","Legacy Forwarder") | eval build=if(isnull(build),"n/a",build) | eval version=if(isnull(version),"pre 4.2",version) | eval guid=if(isnull(guid),sourceHost,guid) | eval os=if(isnull(os),"n/a",os)| eval arch=if(isnull(arch),"n/a",arch) | eval my_splunk_server = splunk_server | fields connectionType sourceIp sourceHost sourcePort destPort kb tcp_eps tcp_Kprocessed tcp_KBps my_splunk_server build version os arch | eval lastReceived = if(kb&amp;gt;0, _time, null) | stats first(sourceIp) as sourceIp first(connectionType) as connectionType first(sourcePort) as sourcePort first(build) as build first(version) as version first(os) as os first(arch) as arch max(_time) as lastConnected max(lastReceived) as lastReceived sum(kb) as kb avg(tcp_eps) as avg_eps by sourceHost | stats first(sourceIp) as sourceIp first(connectionType) as connectionType first(sourcePort) as sourcePort first(build) as build first(version) as version first(os) as os first(arch) as arch max(lastConnected) as lastConnected max(lastReceived) as lastReceived first(kb) as KB first(avg_eps) as eps by sourceHost | eval status = if(isnull(KB) or lastConnected&amp;lt;(info_max_time-900),"missing",if(lastConnected&amp;gt;(lastReceived+300) or KB==0,"quiet","active")) | sort sourceHost
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also, look here for more help: &lt;A href="http://www.splunk.com/wiki/Deploy:Splunk_Metric_Reports" target="_blank"&gt;http://www.splunk.com/wiki/Deploy:Splunk_Metric_Reports&lt;/A&gt; There are a number of useful (and shorter) searches there.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:30:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Dashboard-with-status-of-a-host/m-p/88210#M18310</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2020-09-28T11:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard with status of a host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Dashboard-with-status-of-a-host/m-p/88211#M18311</link>
      <description>&lt;P&gt;awesome.. thanks for the reply.. Will work witht he deployment monitor and the query you have provided. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2012 22:23:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Dashboard-with-status-of-a-host/m-p/88211#M18311</guid>
      <dc:creator>rajbahak</dc:creator>
      <dc:date>2012-03-08T22:23:16Z</dc:date>
    </item>
  </channel>
</rss>

