Hi All,
Please help me with splunk query to find removed (Off-boarded) hosts & index in splunk
Could you please be more specific about the use case? Which hosts, those monitored by Splunk or those running Splunk? Do you also want to detect removed indexes or index removed hosts?
@richgalloway Thanks for your reply.
Splunk query for removed hosts those are monitored by Splunk.
Finding something that is not there is not Splunk's strong suit. See this blog entry for a good write-up on it.
https://www.duanewaddle.com/proving-a-negative/