I wanted to know hosts added to our instance in the last 7 days,
We want to create a report for this,
Thanks in advance
tested and working fine..
| metadata type=hosts |eval SevenDaysBack = relative_time(now(), "-7d@d")
| where firstTime > SevenDaysBack
| eval hostAdded=strftime(firstTime, "%d-%m-%Y %H:%M")
| table host, hostAdded | sort hostAdded
Use the metadata command for the quickest solution to this...
| metadata type=hosts index=*
| fields - firstTime,totalCount,type
| eval filterAge=relative_time(now(),"-7d@d")
| eval ageInSeconds = (now()-recentTime)
| where recentTime > filterAge
| convert ctime(lastTime) ctime(recentTime)
| table host ageInSeconds lastTime recentTime
| sort - ageInSeconds
You can adjust the filterAge using Splunk time modifiers.
thanks for your reply..
In the given query we are getting hosts which were added way before 7 days , actually we wanted to get a list of only new hosts added to our instance