Reporting

View all host

chigueral
Explorer

How can I view all host (wintel or unix)....

Regards

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You're better off running this:

| metadata type=hosts index=*

Will run over all time in no time.

chigueral
Explorer

Thanks a lot....

0 Karma

chandrasekhar4u
Engager

I downvoted this post because it's not an answer

0 Karma

jstockamp
Communicator

if you want to know all the hosts you have index data for do a search

index = "*" | stats count by host

Depending on the size of your indexes this query may take a long time to run.

0 Karma

arimaldo
Explorer

I am seeing INFO in the list of hosts but I don't see where that is coming from. What does it mean and where is it coming from?

0 Karma

arimaldo
Explorer

I found the source and it's coming from the /var/log/rhsm/rhsmcertd.log file. Can I just "blacklist" this entry "INFO" to keep it from showing up in the searches? Are there any drawbacks to do this - e.g. missing log files?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...