Monitoring Splunk

export serverclass hostname

Praz_123
Communicator

How can I export the host values in excel for the particular serverclass 

Is there is any query for that that will be helpful .

Path will be 

Deployment server -> forwarder management ->serverclass -> action (edit clients) -> need to export the hostname from the list 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Praz_123 

Try the following SPL query, which you can then export / save the results of.

| tstats count where index=_dsappevent data.serverClassName=100_IngestAction_AutoGenerated data.action=Install by data.clientId, data.serverClassName
| rename data.* as * 
| table serverClassName clientId 
| append 
    [ tstats count where index=_dsclient by 
        data.build data.clientId data.connectionId data.dns data.guid data.hostname data.instanceId 
        data.instanceName data.ip data.mgmt data.name data.package data.packageType data.splunkVersion data.utsname datetime 
    | dedup data.clientId sortby -datetime 
    | rename data.* as *]
    
| stats values(*) AS * by clientId
| table serverClassName clientId hostname

Replace "100_IngestAction_AutoGenerated" with your chosen serverclass,

 

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...