Splunk Search

How do I join these two searches to get OS type?



When I run the searches below separately, they give me exact result, but when I tried joining them, it was not successful. Is there any way of joining them efficiently? Below are the searches and condition host=hostname.

| metadata type=hosts| sort -recentTime| convert ctime(recentTime) as Last_Report_Time

index=_internal fwdType="*"|dedup sourceHost| table sourceHost, hostname, os
Tags (3)
0 Karma


Hi Sampathu,

what's your intension to do so - do you want to find forwarder not sending and create an alert?

If so don't re-invent the wheel - either use this app https://splunkbase.splunk.com/app/1294/#/overview if your pre Splunk 6.2 or run DMC http://docs.splunk.com/Documentation/Splunk/6.3.0/DMC/DMCoverview

Both have plenty of pre-build alerts to handle this.

Hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...