Splunk Enterprise

Finding hosts in spulnk

Mukunda7
Explorer

So we have a task to find all the hosts in our splunk enterprise. We need to take the list and what type of logs we are getting from that hosts.

How can we do that easily?

Labels (2)
0 Karma

PickleRick
Ultra Champion

It all depends on what you mean by "all hosts" but in general - unless you have a very well organized environment, you might have problems with that.

Why? Because splunk as such doesn't much care about the metadata - it's up to you and your apps to make it reasonable.

For example - if you have a UDP:514 input receiving syslog events and you receive events from ten different hosts which are misconfigured and are sending "localhost" as their name, splunk will probably parse the host field as "localhost" from the event contents and the source by default would be set to "udp:514". It doesn't tell you much, does it?

There's no "automatic" additional metadata that splunk captures - like source IP for network connections.

So even though you might list metadata about all your events (list all your sources, hosts and sourcetypes) it still might not correspond directly to your physical environment.

0 Karma

Mukunda7
Explorer

Got your point but what we are looking is from which servers we are mainly getting data for last 30 days. can we find that ?

so that we can list those important servers and will blocklist the remaining.

0 Karma

PickleRick
Ultra Champion

As I wrote, earlier - you can list what you have in indexes. Just do

| tstats count where index=* by index,source,sourcetype

 and you're all set.

It's just that you might end up with data which tells you absolutely nothing.

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@Mukunda7 

| metadata type=hosts index=* | fields host

index=* is not a great search you can limit it if you know the index name.

---

Hope it helps!

 

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...