Splunk Search

Check multiple hosts for existence

seva98
Path Finder

I have list of around 100 hosts that are sending data to index and I would love to return a table with hostname and status of 0 (didn't receive any date from it in selected time range) and 1 (did receive the data).

I am able to search through multiple hosts with OR like `host=test1 OR host=test2 OR ...` but I am not sure how to display status 0 at hosts that are not found.

What would be efficient solution for this please?

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
See https://www.duanewaddle.com/proving-a-negative/
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust
See https://www.duanewaddle.com/proving-a-negative/
---
If this reply helps you, Karma would be appreciated.

seva98
Path Finder

Thanks Rich, that is so simple but also very scaleable solution.

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...