Getting Data In

Remove Zero Event Host

ITSD
Explorer

I'd already use "| delete" try to delete host, but it still remain there with event count 0. How could I remove no more need event source?

Tags (1)
0 Karma

ITSD
Explorer

I'd use | metadata type=hosts index=main | convert ctime(recentTime) as Recent_Time | where lastTime < (now() -3600)

to check no events host every hour, but get this result 12/16/2010 17:23:01 9223372036854775807 xxx.xx.xx.xx 0 1292491381 0 hosts

I'd remove xxx.xx.xx.xx with | delete but still show there how could I fix it?

Thanks

0 Karma

ayme
Splunk Employee
Splunk Employee

I believe this was identified and addressed in Splunk 4.1.6 4.1.6 release notes

Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

&#x1f5e3; You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...