Monitoring Splunk

export serverclass hostname

Praz_123
Communicator

How can I export the host values in excel for the particular serverclass 

Is there is any query for that that will be helpful .

Path will be 

Deployment server -> forwarder management ->serverclass -> action (edit clients) -> need to export the hostname from the list 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Praz_123 

Try the following SPL query, which you can then export / save the results of.

| tstats count where index=_dsappevent data.serverClassName=100_IngestAction_AutoGenerated data.action=Install by data.clientId, data.serverClassName
| rename data.* as * 
| table serverClassName clientId 
| append 
    [ tstats count where index=_dsclient by 
        data.build data.clientId data.connectionId data.dns data.guid data.hostname data.instanceId 
        data.instanceName data.ip data.mgmt data.name data.package data.packageType data.splunkVersion data.utsname datetime 
    | dedup data.clientId sortby -datetime 
    | rename data.* as *]
    
| stats values(*) AS * by clientId
| table serverClassName clientId hostname

Replace "100_IngestAction_AutoGenerated" with your chosen serverclass,

 

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...