Getting Data In

Group hosts by Sourcetype by Index

king2jd
Path Finder

Hello,

I am trying to perform a search that groups all hosts by sourcetype and groups those sourcetypes by index. So far I have this:

| tstats values(host) AS Host, values(sourcetype) AS Sourcetype WHERE index=* by index

But this search does map each host to the sourcetype. Instead it shows all the hosts that have at least one of the resulting sourcetypes as a sourcetype.

0 Karma
1 Solution

rjthibod
Champion

How about this?

| tstats count where index=* by index sourcetype host 
| stats list(host) as Hosts by index sourcetype

View solution in original post

rjthibod
Champion

How about this?

| tstats count where index=* by index sourcetype host 
| stats list(host) as Hosts by index sourcetype

king2jd
Path Finder

Does exactly what I needed. Thanks for your help!

0 Karma

gcusello
SplunkTrust
SplunkTrust

have you tried
stats count by host, sourcetype, index OR tstats count by host, sourcetype, index ?

Bye.
Giuseppe

0 Karma

rjthibod
Champion

Can you give an example of what the end data should look like in table format?

0 Karma

king2jd
Path Finder

Index1----sourcetype1-----host1
------host2
------sourcetype2---host 3
Index2-----sourcetype3----host1
----host5

Does this help you?

0 Karma

king2jd
Path Finder

That came out worse than I thought but essentially
index1-sourcetype1-host1,host2
index2-sourcertype2-host1,host4

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...