<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I lookup the Name &amp;amp; IP addresses of my Splunk instances. Am using the following for ES but don't get the in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571039#M10377</link>
    <description>&lt;P&gt;Apologies, I was able to run this command in my environment and got results.&amp;nbsp;&lt;BR /&gt;index=_internal sourcetype=splunkd group=tcpin_connections (hostname="server1" OR hostname="server2")| stats latest(sourceIp) by hostname&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you modifying the hostname variables to match your environment's servernames?&lt;/P&gt;</description>
    <pubDate>Thu, 14 Oct 2021 18:04:37 GMT</pubDate>
    <dc:creator>Stefanie</dc:creator>
    <dc:date>2021-10-14T18:04:37Z</dc:date>
    <item>
      <title>How do I lookup the Name &amp; IP addresses of my Splunk instances. Am using the following for ES but don't get the IP. Thx</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571014#M10371</link>
      <description>&lt;P class="yiv7137020218MsoNormal"&gt;&lt;SPAN&gt;The following do not give the IP for the Splunk Enterprise Security (ES). Is there a better SPL to provide the list of all Splunk instances names, IPs. Specially the ES? Thanks a million in advance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="yiv7137020218MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="yiv7137020218MsoNormal"&gt;&lt;SPAN&gt;| rest /services/server/sysinfo splunk_server=local | table splunk_server&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="yiv7137020218MsoNormal"&gt;&lt;SPAN&gt;| rest /services/server/sysinfo splunk_server=local | table splunk_server | lookup dnslookup clienthost as splunk_server OUTPUT clienthost as ipAddress&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="yiv7137020218MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 15:47:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571014#M10371</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-10-14T15:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do I lookup the Name &amp; IP addresses of my Splunk instances. Am using the following for ES but don't get the</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571023#M10372</link>
      <description>&lt;P&gt;You can try modifying this search to give you only the hostnames of your Splunk servers.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunkd group=tcpin_connections | stats latest(sourceIp) by hostname&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 14 Oct 2021 16:42:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571023#M10372</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2021-10-14T16:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do I lookup the Name &amp; IP addresses of my Splunk instances. Am using the following for ES but don't get the</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571027#M10373</link>
      <description>&lt;P&gt;Thank u for your reply. Your SPL provides all the hosts in my environment that are many. How do I just look up the IPs of the 12 Splunk instances that I have like ES, SHs, License server etc. ? Thank u&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 17:02:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571027#M10373</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-10-14T17:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: How do I lookup the Name &amp; IP addresses of my Splunk instances. Am using the following for ES but don't get the</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571032#M10374</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunkd group=tcpin_connections (hostname=server1 OR hostname=server2 OR hostname=server3) | stats latest(sourceIp) by hostname&lt;/LI-CODE&gt;&lt;P&gt;This is a basic way to add your Splunk server names.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 17:27:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571032#M10374</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2021-10-14T17:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do I lookup the Name &amp; IP addresses of my Splunk instances. Am using the following for ES but don't get the</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571036#M10375</link>
      <description>&lt;P&gt;Thank u very much for your message. I ran your last SPL on a Search head &amp;amp; on my cluster master , no results were produced. Please advise.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 17:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571036#M10375</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-10-14T17:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: How do I lookup the Name &amp; IP addresses of my Splunk instances. Am using the following for ES but don't get the</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571039#M10377</link>
      <description>&lt;P&gt;Apologies, I was able to run this command in my environment and got results.&amp;nbsp;&lt;BR /&gt;index=_internal sourcetype=splunkd group=tcpin_connections (hostname="server1" OR hostname="server2")| stats latest(sourceIp) by hostname&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you modifying the hostname variables to match your environment's servernames?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 18:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571039#M10377</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2021-10-14T18:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: How do I lookup the Name &amp; IP addresses of my Splunk instances. Am using the following for ES but don't get the</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571165#M10378</link>
      <description>&lt;P&gt;Thanks again , I got no results. I even ran it with index=* and got no results.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 20:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571165#M10378</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-10-15T20:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do I lookup the Name &amp; IP addresses of my Splunk instances. Am using the following for ES but don't get the</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571223#M10379</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228649"&gt;@SamHTexas&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Please try the below SPL, it should show all your Splunk Infrastructure hostname, roles, and IP addresses. Unknown roles are being set as Heavy Forwarder.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal earliest=-24h source="*metrics.log" group=per_index_thruput series=_audit 
| stats count by host 
| fields host 
| append 
    [ search index=_internal earliest=-15m source="*splunkd_access.log" uri_path="/services/search/jobs/export" 
    | stats count by host 
    | fields host 
    | eval role="Search Head"] 
| append 
    [ search index=_internal earliest=-15m source="*splunkd_access.log" uri_path="/servicesNS/-/SplunkEnterpriseSecuritySuite/admin/summarization" 
    | stats count by host 
    | fields host 
    | eval role="Enterprise Security"] 
| append 
    [| rest /services/search/distributed/peers 
    | fields host title 
    | rex field=title "(?&amp;lt;ip&amp;gt;[^:]+)" 
    | table host ip] 
| append 
    [ search earliest=-15m index=_internal source="*metrics.log" group=tcpin_connections destPort=9997 
    | stats count by host 
    | fields host 
    | eval role="Indexer"] 
| append 
    [ search earliest=-120m index=_internal source="*metrics.log" name=instance TERM(shc_deployer) 
    | stats count by host 
    | fields host 
    | eval role="SHCluster Deployer"] 
| append 
    [ search earliest=-15m index=_internal source="*metrics.log" group=shclustering 
    | stats count by host 
    | fields host 
    | eval role="SHCluster Member"] 
| append 
    [ search earliest=-15m index=_internal source="*health.log" node_type=category node_path="splunkd.search_head_clustering.shc_captain" 
    | stats latest(host) as host 
    | eval role="SHCluster Captain"] 
| append 
    [ search earliest=-15m index=_internal source="*metrics.log" group=cmmaster_* 
    | stats count by host 
    | fields host 
    | eval role="Cluster Master"] 
| append 
    [ search earliest=-15m index=_internal source="*metrics.log" group=deploy-server name=clients nTotal&amp;gt;0 
    | stats count by host 
    | fields host 
    | eval role="Deployment Server"] 
| append 
    [ search earliest=-15m index=_internal LicenseUsage sourcetype=splunkd type=Usage 
    | stats latest(host) as host 
    | eval role="License Master"] 
| append 
    [ search index=_internal source="*metrics.log" group=tcpin_connections fwdType=full 
    | stats latest(sourceIp) as ip by hostname 
    | rename hostname as host] 
| stats values(role) as role values(ip) as ip by host 
| fillnull value="Heavy Forwarder" role 
| sort role&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Oct 2021 21:39:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-lookup-the-Name-amp-IP-addresses-of-my-Splunk-instances/m-p/571223#M10379</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-10-16T21:39:46Z</dc:date>
    </item>
  </channel>
</rss>

