Getting Data In

Number of hosts over time

hartfoml
Motivator

I am looking for a good way to show the number of host that are sending log files to splunk over time

I can use timechart but how do I count uniq host names and from what index. I tried _internal for the metrics and summary but when i use uniq or dedup it kills my timchart function.

How to get the number for each day over a 30 day????

I tried this:

index=_internal hostname="*" component="Metrics" | timechart span=d count(uniq hostname)

But that's not right. anyone know the right way??

Tags (1)
0 Karma
1 Solution

BobM
Builder

This will give what you want.

index=_internal per_host_thruput | timechart span=1d dc(series) as hosts

dc is short for distinct count and series contains the host name in the per_host group

View solution in original post

BobM
Builder

This will give what you want.

index=_internal per_host_thruput | timechart span=1d dc(series) as hosts

dc is short for distinct count and series contains the host name in the per_host group

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...