Getting Data In

How to list hosts with no events

Susannajuurinen
Explorer

Hi! I'm trying to find out hosts that are not sending any data to Splunk at certain time frame. Using command "host=* | chart count by host" I can get a list of hosts with event count summary, but it doesn't show those where the value is 0. Is there a way to get a list of hosts with no events?
Thanks!

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

This should help. Note that when the search comes back empty you don't have any hosts that are not currently sending data during the specific time period.

http://splunk-base.splunk.com/answers/3181/how-do-i-alert-when-a-host-stops-sending-data

Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...

New Splunk Innovations Enhance Performance and Accelerate Troubleshooting

Splunk is excited to announce new releases that empower ITOps and engineering teams to stay ahead in ever ...