Getting Data In

Number of hosts over time

hartfoml
Motivator

I am looking for a good way to show the number of host that are sending log files to splunk over time

I can use timechart but how do I count uniq host names and from what index. I tried _internal for the metrics and summary but when i use uniq or dedup it kills my timchart function.

How to get the number for each day over a 30 day????

I tried this:

index=_internal hostname="*" component="Metrics" | timechart span=d count(uniq hostname)

But that's not right. anyone know the right way??

Tags (1)
0 Karma
1 Solution

BobM
Builder

This will give what you want.

index=_internal per_host_thruput | timechart span=1d dc(series) as hosts

dc is short for distinct count and series contains the host name in the per_host group

View solution in original post

BobM
Builder

This will give what you want.

index=_internal per_host_thruput | timechart span=1d dc(series) as hosts

dc is short for distinct count and series contains the host name in the per_host group

Get Updates on the Splunk Community!

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...

Splunk SOAR Now Available on Google Cloud Platform

We’re excited to announce that Splunk SOAR is now natively available as a SaaS solution on Google Cloud ...