Deployment Architecture

How to get list of hosts added to our instance in the last 7 days?

kiran_mh
Explorer

Hi,

I wanted to know hosts added to our instance in the last 7 days,

We want to create a report for this,

Kindly help..

Thanks in advance

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

tested and working fine..

| metadata type=hosts |eval SevenDaysBack = relative_time(now(), "-7d@d") 
| where firstTime > SevenDaysBack 
| eval hostAdded=strftime(firstTime, "%d-%m-%Y %H:%M") 
| table host, hostAdded | sort hostAdded

alt text

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Use the metadata command for the quickest solution to this...

| metadata type=hosts index=*
| fields - firstTime,totalCount,type
| eval filterAge=relative_time(now(),"-7d@d")
| eval ageInSeconds = (now()-recentTime)
| where recentTime > filterAge
| convert ctime(lastTime) ctime(recentTime)
| table host ageInSeconds lastTime recentTime 
| sort - ageInSeconds

You can adjust the filterAge using Splunk time modifiers.

0 Karma

kiran_mh
Explorer

thanks for your reply..

In the given query we are getting hosts which were added way before 7 days , actually we wanted to get a list of only new hosts added to our instance

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...