Splunk Search

Grouping by hosts

jylee
New Member

Is there a way for me to group all events by a list of hosts in one data center and then group all events by another list of hosts in another data center?

Specifically, I'd like to determine a traffic comparison between two sets of servers

Tags (1)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

You could use the tagging feature to identify hosts by location. See link below. If you have a large number of hosts you might want to use a look up and have that list of hosts come from a .csv file, for example.

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Tagthehostfield

... tag = datacenter1

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

You could use the tagging feature to identify hosts by location. See link below. If you have a large number of hosts you might want to use a look up and have that list of hosts come from a .csv file, for example.

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Tagthehostfield

... tag = datacenter1

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...