Getting Data In

Remove Zero Event Host

Explorer

I'd already use "| delete" try to delete host, but it still remain there with event count 0. How could I remove no more need event source?

Tags (1)
0 Karma

Explorer

I'd use | metadata type=hosts index=main | convert ctime(recentTime) as Recent_Time | where lastTime < (now() -3600)

to check no events host every hour, but get this result 12/16/2010 17:23:01 9223372036854775807 xxx.xx.xx.xx 0 1292491381 0 hosts

I'd remove xxx.xx.xx.xx with | delete but still show there how could I fix it?

Thanks

0 Karma

Splunk Employee
Splunk Employee

I believe this was identified and addressed in Splunk 4.1.6 4.1.6 release notes

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!