We are using 100+ machines...Could you please help me in splunk search...
The scenario is I am having 100 machines and I have to create an alert for the machines that are not reporting for last 24 hours.....Could you please help me in the coding part of it...
Hi
https://community.splunk.com/t5/Splunk-Enterprise/Query-and-Reporting/m-p/511372#M2840
you could find same kind of discussion and links to other guidelines.
r. Ismo
Finding something that is not there is not Splunk's strong suit. See this blog entry for a good write-up on it.
https://www.duanewaddle.com/proving-a-negative/
Thank you....all my machines reboot everyday....so is it possible to check if all the machines are reporting based on reboot