index = XXX Sourcetype="YYY" host="ZZZ_IN_*" | stats count by host will display all the nodes which are up and running in the tier.
If any one ore two nodes are down, how can i create an alert for it.
Explaining about our problem: The nodes have both IIS and App logs which are stored in separate drives. Once the IIS logs are full also we will not receive an alert using metadata query, since splunkuniversal forwarder are capturing the logs from App logs. So we went for the above query but couldn't able to make out the result. Thanks in advance for your help.