- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Query to find removed hosts
alexspunkshell
Contributor
01-28-2021
05:24 AM
Hi All,
Please help me with splunk query to find removed (Off-boarded) hosts & index in splunk
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
01-28-2021
05:55 AM
Could you please be more specific about the use case? Which hosts, those monitored by Splunk or those running Splunk? Do you also want to detect removed indexes or index removed hosts?
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
alexspunkshell
Contributor
01-28-2021
06:22 AM
@richgalloway Thanks for your reply.
Splunk query for removed hosts those are monitored by Splunk.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
01-28-2021
11:53 AM
Finding something that is not there is not Splunk's strong suit. See this blog entry for a good write-up on it.
https://www.duanewaddle.com/proving-a-negative/
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
