Getting Data In

Number of hosts over time

hartfoml
Motivator

I am looking for a good way to show the number of host that are sending log files to splunk over time

I can use timechart but how do I count uniq host names and from what index. I tried _internal for the metrics and summary but when i use uniq or dedup it kills my timchart function.

How to get the number for each day over a 30 day????

I tried this:

index=_internal hostname="*" component="Metrics" | timechart span=d count(uniq hostname)

But that's not right. anyone know the right way??

Tags (1)
0 Karma
1 Solution

BobM
Builder

This will give what you want.

index=_internal per_host_thruput | timechart span=1d dc(series) as hosts

dc is short for distinct count and series contains the host name in the per_host group

View solution in original post

BobM
Builder

This will give what you want.

index=_internal per_host_thruput | timechart span=1d dc(series) as hosts

dc is short for distinct count and series contains the host name in the per_host group

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...