All our servers should have more than 2 apps installed. We run this report for a list of systems missing apps:
| rest /services/deployment/server/clients splunk_server=local| table hostname applications*.stateOnClient | untable hostname applications value | stats count by hostname | where count < 3
However, I would also like to include the host's IP address in this, but I can't figure out how to include it.
Any pointers or better ways to go about this?