Hello fellow splunkers,
Fairly remedial question but I have a heavy forwarder that has stopped reporting to splunk and need to find the IP of it. I currently run the following search in order to find all hosts reporting within a specific time period but I can only see hosts name and not IP. Is there any way of easily location the IP of a host?
index=internal sourcetype=splunkd group=tcpinconnections | stats first(version) by hostname
The forwarder is down currently, I want to find the IP of it from when it was last reporting successfully.
Just do your stats by sourceIp instead of hostname?
index=_internal sourcetype=splunkd group=tcpin_connections | stats first(version) latest(sourceIp) by hostname