Splunk Search

How do i get a count of all my assets by Splunk Version by Os

veryfoot
Path Finder

Hi Splunkers,

I'm new in the Splunk world.

I'm trying for a reporting tasks, to obtain the counting of every Client or server (all asset with splunk deamon) by version of splunk release by Os type.

Im not familiat with "stats" command.

I tryed somthings like this :

 

index="_internal" sourcetype="splunkd" group=tcpin_connections (os=windows OR os=linux) (version=7* OR version=8*) 
| table version, os, hostname
| dedup hostname
| stats count as hostname by version,os

 

But the results seems to be incorrect. I cant figure it out what i am doing wrong in order to obtain something like this :

 

Splunk version  | os      | Hostname_count_result
8.x.x           | linux   | sum of hostnames
8.x.x           | windows | sum of hostnames
7.x.x           | linux   | sum of hostnames
7.x.x           | windows | sum of hostnames

 

Many thanks for your returns !

Regards

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You have the right idea.  This works for me and is little more performant.  I added version=9* because I don't have any version 7 or 8 instances.

index="_internal" sourcetype="splunkd" group=tcpin_connections (os=windows OR os=linux) (version=7* OR version=8* OR version=9*)
| fields version, os, hostname
| stats dc(hostname) as hostname by version,os

What made you think the original results were incorrect?

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You have the right idea.  This works for me and is little more performant.  I added version=9* because I don't have any version 7 or 8 instances.

index="_internal" sourcetype="splunkd" group=tcpin_connections (os=windows OR os=linux) (version=7* OR version=8* OR version=9*)
| fields version, os, hostname
| stats dc(hostname) as hostname by version,os

What made you think the original results were incorrect?

---
If this reply helps you, Karma would be appreciated.

veryfoot
Path Finder

Hi and many thank for your fast return.

About my doubts of my results, I think i wasnt sure that the counting were correct, beacause I have more than 20 000 assets... The usage of the "stats" command is for now, a bit foggy to me. So i wasnt sure of my search request.

While trying differents things, the differents results was not concordants... so I wanted to check that my method was correct.

Many thanks again for the solution, it do perfectly the result I needed !

Best regards my new Splunk friend ^^

 

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...