Good day
Currently receives a master Splunk server log files from 3 other splunk server.
I created a dashboard for each Splunkserver.
"Errors in the last 24h", I added each host.
http://img4web.com/view/2A75Q9
How can I add only the Splunkserver so I do not add each host?
thank you
How can I add only the Splunkserver so I do not add each host?
If by splunkserver you mean the indexer where the events have been indexes,
you can use splunk_server=myindexerA.
How can I add only the Splunkserver so I do not add each host?
If by splunkserver you mean the indexer where the events have been indexes,
you can use splunk_server=myindexerA.