Monitoring Splunk

Report generate

sahildb
Engager

We need to generate report in splunk which can tell us my log sources and all server details are reporting to splunk.

 

 

is there any query we can use to fetch all the details.

Labels (1)
0 Karma
1 Solution

manjunathmeti
Champion

Hi @sahildb ,

Use tstats command to get the data.

| tstats count where index="*" by host

| tstats count where index="*" by source

 

If this reply helps you, an upvote/like would be appreciated.

View solution in original post

0 Karma

manjunathmeti
Champion

Hi @sahildb ,

Use tstats command to get the data.

| tstats count where index="*" by host

| tstats count where index="*" by source

 

If this reply helps you, an upvote/like would be appreciated.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...