Deployment Architecture

How to determine which servers are ingesting data into our Splunk instance?


my instance is search head for our project. so i want to know the servers which are ingesting into only my instance with ip address ****

0 Karma

Revered Legend

Give this a try

| tstats count WHERE index=* splunk_server=YOurInstanceName by host index| table host index
0 Karma


Try this: |metadata index=* type=hosts

over "All-Time"

0 Karma


not working
splunk_server=*38-20|dedup host index|table host index

is this works??

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!