Hello fellow splunkers,
Fairly remedial question but I have a heavy forwarder that has stopped reporting to splunk and need to find the IP of it. I currently run the following search in order to find all hosts reporting within a specific time period but I can only see hosts name and not IP. Is there any way of easily location the IP of a host?
index=_internal sourcetype=splunkd group=tcpin_connections | stats first(version) by hostname
Just do your stats by sourceIp instead of hostname?
Or do:
index=_internal sourcetype=splunkd group=tcpin_connections | stats first(version) latest(sourceIp) by hostname
Just do your stats by sourceIp instead of hostname?
Or do:
index=_internal sourcetype=splunkd group=tcpin_connections | stats first(version) latest(sourceIp) by hostname
Excellent!
Thanks Frank!
Ping the hostname perhaps on a terminal? It resolves by itself.
The forwarder is down currently, I want to find the IP of it from when it was last reporting successfully.