Deployment Architecture

How to get list of hosts added to our instance in the last 7 days?

kiran_mh
Explorer

Hi,

I wanted to know hosts added to our instance in the last 7 days,

We want to create a report for this,

Kindly help..

Thanks in advance

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

tested and working fine..

| metadata type=hosts |eval SevenDaysBack = relative_time(now(), "-7d@d") 
| where firstTime > SevenDaysBack 
| eval hostAdded=strftime(firstTime, "%d-%m-%Y %H:%M") 
| table host, hostAdded | sort hostAdded

alt text

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Use the metadata command for the quickest solution to this...

| metadata type=hosts index=*
| fields - firstTime,totalCount,type
| eval filterAge=relative_time(now(),"-7d@d")
| eval ageInSeconds = (now()-recentTime)
| where recentTime > filterAge
| convert ctime(lastTime) ctime(recentTime)
| table host ageInSeconds lastTime recentTime 
| sort - ageInSeconds

You can adjust the filterAge using Splunk time modifiers.

0 Karma

kiran_mh
Explorer

thanks for your reply..

In the given query we are getting hosts which were added way before 7 days , actually we wanted to get a list of only new hosts added to our instance

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...