Getting Data In
Highlighted

How to find IP address of a host reporting in Splunk?

Explorer

Hello fellow splunkers,

Fairly remedial question but I have a heavy forwarder that has stopped reporting to splunk and need to find the IP of it. I currently run the following search in order to find all hosts reporting within a specific time period but I can only see hosts name and not IP. Is there any way of easily location the IP of a host?

index=internal sourcetype=splunkd group=tcpinconnections | stats first(version) by hostname

0 Karma
Highlighted

Re: How to find IP address of a host reporting in Splunk?

Communicator

Ping the hostname perhaps on a terminal? It resolves by itself.

0 Karma
Highlighted

Re: How to find IP address of a host reporting in Splunk?

Explorer

The forwarder is down currently, I want to find the IP of it from when it was last reporting successfully.

0 Karma
Highlighted

Re: How to find IP address of a host reporting in Splunk?

Ultra Champion

Just do your stats by sourceIp instead of hostname?

Or do:

index=_internal sourcetype=splunkd group=tcpin_connections | stats first(version) latest(sourceIp) by hostname

View solution in original post

Highlighted

Re: How to find IP address of a host reporting in Splunk?

Explorer

Excellent!

Thanks Frank!

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.