hey, could you provide some sample events?
If all of the columns are already extracted then with the columns provided then you can try something like this
index=<your_index> | table Hostname OS IPaddress LastLogReceived
let me know if this helps!
hey, could you provide some sample events?
If all of the columns are already extracted then with the columns provided then you can try something like this
index=<your_index> | table Hostname OS IPaddress LastLogReceived
let me know if this helps!
Hi Mayurr98,
Thanks for the help.
I need something like this in my report
|Srv1 | 10.x.x.x| Windows|
|Srv2 | 10.x.x.x| Windows|
|Srv3 | 10.x.x.x| Windows|
|Tot Srv = 3(count of servers)|
Below is my search which i used for daily report, on top of this query i also need to count number of hostname that are present in this search result.
index= _internal fwdType ="*"
|eval lastUpdate=strftime(_time, "%d - %m -%Y %H:%M:%S")
|dedup hostname
| sort hostname asc
| table hostname, os, sourceHost, lastupdate
Try this :
index=_internal fwdType="*"
| eval lastUpdate=strftime(_time,"%d-%m-%Y %H:%M:%S")
| dedup hostname
| stats dc(hostname) as dc_count by hostname, os, sourceHost, lastUpdate
| sort hostname asc
| addcoltotals dc_count labelfield=hostname label="Total SRV"
Thanks Mayurr98.
Worked for me to certain level.