Deployment Architecture

How to get list of hosts added to our instance in the last 7 days?

kiran_mh
Explorer

Hi,

I wanted to know hosts added to our instance in the last 7 days,

We want to create a report for this,

Kindly help..

Thanks in advance

Tags (1)
0 Karma

inventsekar
Ultra Champion

tested and working fine..

| metadata type=hosts |eval SevenDaysBack = relative_time(now(), "-7d@d") 
| where firstTime > SevenDaysBack 
| eval hostAdded=strftime(firstTime, "%d-%m-%Y %H:%M") 
| table host, hostAdded | sort hostAdded

alt text

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Use the metadata command for the quickest solution to this...

| metadata type=hosts index=*
| fields - firstTime,totalCount,type
| eval filterAge=relative_time(now(),"-7d@d")
| eval ageInSeconds = (now()-recentTime)
| where recentTime > filterAge
| convert ctime(lastTime) ctime(recentTime)
| table host ageInSeconds lastTime recentTime 
| sort - ageInSeconds

You can adjust the filterAge using Splunk time modifiers.

0 Karma

kiran_mh
Explorer

thanks for your reply..

In the given query we are getting hosts which were added way before 7 days , actually we wanted to get a list of only new hosts added to our instance

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...