<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get only active hosts? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-only-active-hosts/m-p/627891#M218149</link>
    <description>&lt;P&gt;That worked perfectly! Thank you so much for the help!&lt;/P&gt;</description>
    <pubDate>Sat, 21 Jan 2023 20:19:07 GMT</pubDate>
    <dc:creator>Stephcg</dc:creator>
    <dc:date>2023-01-21T20:19:07Z</dc:date>
    <item>
      <title>How to get only active hosts?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-only-active-hosts/m-p/627852#M218143</link>
      <description>&lt;P&gt;I have an application that have some instances/hosts. Because of change of throughput or instability new instances/hosts can be initiated and old can be terminated.&lt;BR /&gt;There are many different events/logs being registered.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When a new instance/host is initiated it shows the following event/log:&lt;/P&gt;&lt;TABLE width="776px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="108.969px"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;1/20/23&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;6:00:01.256 PM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="666.031px"&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;[&lt;SPAN class=""&gt;app=gateway-example-app&lt;/SPAN&gt;, &lt;SPAN class=""&gt;traceId=&lt;/SPAN&gt;, &lt;SPAN class=""&gt;spanId=&lt;/SPAN&gt;, &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt; [ &lt;SPAN class=""&gt;main&lt;/SPAN&gt;] &lt;SPAN class=""&gt;gateway.GatewayApplicationKt&lt;/SPAN&gt; &lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Started&lt;/SPAN&gt; &lt;SPAN class=""&gt;GatewayApplicationKt&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;21.081&lt;/SPAN&gt; &lt;SPAN class=""&gt;seconds&lt;/SPAN&gt; (&lt;SPAN class=""&gt;JVM&lt;/SPAN&gt; &lt;SPAN class=""&gt;running&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;48.641)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;SPAN class=""&gt;host = ip-example-of-ip-01&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;source = http:source-example&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;sourcetype = example-sourcetype&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When an instance is terminated, it shows the following log:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;1/20/23&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3:53:42.778 PM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;CoreServiceImpl&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;INFO:&lt;/SPAN&gt; &lt;SPAN class=""&gt;JVM&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;shutting&lt;/SPAN&gt; &lt;SPAN class=""&gt;down&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;SPAN class=""&gt;host = ip-example-of-ip-02&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;source = http:source-example&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;sourcetype = example-sourcetype&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Is there a way of getting a list of hosts that have the log of initialization, but don't have the log of termination?&amp;nbsp;&lt;BR /&gt;In other words, a list of currently active hosts?&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you for any help in advance. And sorry if I wrote anything wrong, english is not my main language.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 00:24:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-only-active-hosts/m-p/627852#M218143</guid>
      <dc:creator>Stephcg</dc:creator>
      <dc:date>2023-01-21T00:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to get only active hosts?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-only-active-hosts/m-p/627856#M218144</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252885"&gt;@Stephcg&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There are other ways but the below should work for your case;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=application source=http:source-example sourcetype=example-sourcetype ("is shutting down" OR "Started") 
| dedup host 
| search "Started"
| table _time host&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 02:21:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-only-active-hosts/m-p/627856#M218144</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-01-21T02:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to get only active hosts?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-only-active-hosts/m-p/627891#M218149</link>
      <description>&lt;P&gt;That worked perfectly! Thank you so much for the help!&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 20:19:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-only-active-hosts/m-p/627891#M218149</guid>
      <dc:creator>Stephcg</dc:creator>
      <dc:date>2023-01-21T20:19:07Z</dc:date>
    </item>
  </channel>
</rss>

