Other Usage

Splunk Report to identify hosts/containers that are not reporting anything

prachijain1288
Loves-to-Learn Everything

Hello All,

I have an inputlookup csv file that contains a list of host and corresponding docker containers running on those hosts for my environment. I am trying to generate a report where I can report daily list of host+containers that have not sent any logs to splunk for that particular day. Stats count does not return 0 event count. I am trying to get something like below:


Monday                                 Tuesday                           Wednesday                   Thursday                              Friday

host1-containerx             host3-containerx         host4-containerx.       host5-containerx              ---

host1-containery            host3-containery         host5-containerx

host2-containerz          host3-containerz

host1-containery

host2-containerz

 

 

I would appreciate any help 🙂

 

Thank you !!

Labels (1)
0 Karma

efavreau
Motivator

@prachijain1288  Try to search for your answer in the community to see if the question has already been asked. As ITWhisperer indicates, this comes up. A lot. Also, you want to try to tell us what you've tried, what the result was, why the result doesn't meet your expectations, and what your expectations were. This helps us figure out what a possible solution might be.

To give you one possible lead to your question, try reading this and if that doesn't help, use the link ITWhisperer created.
https://community.splunk.com/t5/Splunk-Search/Display-hosts-with-no-data/m-p/293342

 

###

If this reply helps you, an upvote would be appreciated.
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could start here 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...