- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to list hosts with no events
Susannajuurinen
Explorer
03-22-2013
06:32 AM
Hi! I'm trying to find out hosts that are not sending any data to Splunk at certain time frame. Using command "host=* | chart count by host" I can get a list of hosts with event count summary, but it doesn't show those where the value is 0. Is there a way to get a list of hosts with no events?
Thanks!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sdaniels

Splunk Employee
03-22-2013
06:37 AM
This should help. Note that when the search comes back empty you don't have any hosts that are not currently sending data during the specific time period.
http://splunk-base.splunk.com/answers/3181/how-do-i-alert-when-a-host-stops-sending-data
