I'm trying to rename the IP's of our servers to splunknodes
host_ip host_name
ip-111-11-1-11 | Searchhead |
ip-111-11-1-12 | Searchhead |
ip-111-11-1-10 | Masternode |
ip-111-11-2-11 | Indexer |
ip-111-11-2-12 | Indexer |
ip-111-11-2-10 | Deploymentserver |
How do I get it to count the duplicates?:
host_ip host_name
ip-111-11-1-11 | Searchhead1 |
ip-111-11-1-12 | Searchhead2 |
ip-111-11-1-10 | Masternode |
ip-111-11-2-11 | Indexer1 |
ip-111-11-2-12 | Indexer2 |
ip-111-11-2-10 | Deploymentserver |
Thanks in advance!
Hi!! try this:
your search
| streamstats count by host_name
| eval host_name=host_name.count
| fields - count
Hi!! try this:
your search
| streamstats count by host_name
| eval host_name=host_name.count
| fields - count