Getting Data In

How to get the count of forwarders that are reporting from each application/Workspace?

yu94
New Member

Hi Splunkers,

I want to get the count of forwarders that are reporting from each application/Workspace.

Example: I have created 4 apps/workspace for 4 different teams.
So now I want to get the count of forwarders that are reporting from each application/Workspace

Is there any search which can give me the above information in a single search ?

Thanks in advance,
Thippesh

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi yu94,
you could create a lookup with your application/Workspace (es. AppWork.csv) in which there are indexes or sourcetypes or another field that is unique used in your applications, something like this:

App Index Sourcetype
App1 index1 sourcetype1
App1 Index1 sourcetype2
App2 index2 sourcetype3
...

and then (using sourcetype) run a search like this

| inputlooup AppWork.csv 
| eval count=0 
| append [ index=* | stats count by sourcetype]
| stats sum(count) AS Total by sourcetype
| lookup AppWork.csv sourcetype OUTPUT App
| stats values(sourcetype) AS sourcetype sum(Total) AS Total by App

You could limit your results inserting in the sub-search the correct indexes (I don't know them) and (if you have other sourcetypes than the lookup) eventually filter sub-search by your lookup:

| inputlooup AppWork.csv 
| eval count=0 
| append 
     [ index=*  [  | inputlooup AppWork.csv | dedup sourcetype | fields sourcetype]
     | stats count by sourcetype
     ]
| stats sum(count) AS Total by sourcetype
| lookup AppWork.csv sourcetype OUTPUT App
| stats values(sourcetype) AS sourcetype sum(Total) AS Total by App

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...