We have list of hots not logging lookup hosts list can any one help with search to search in splunk find out why they are not logging
Try this search on your DS,
|inputlookup dmc_forwarder_assets | search status="missing" | fields hostname os arch forwarder_type version last_connected status | rename hostname as Instance | eval now=now() | eval Duration_Not_Connected=now-last_connected | where Duration_Not_Connected<=2592000 | fields - last_connected now | sort Duration_Not_Connected | eval Duration_Not_Connected_Days = round(Duration_Not_Connected/86400,0)
Try this search on your DS,
|inputlookup dmc_forwarder_assets | search status="missing" | fields hostname os arch forwarder_type version last_connected status | rename hostname as Instance | eval now=now() | eval Duration_Not_Connected=now-last_connected | where Duration_Not_Connected<=2592000 | fields - last_connected now | sort Duration_Not_Connected | eval Duration_Not_Connected_Days = round(Duration_Not_Connected/86400,0)
Thanks ! sbbadri
That is a pretty vague question so the best we can do is give you similarly vague help. Start here:
https://www.splunk.com/blog/2012/10/02/tips-and-tricks-for-the-new-guy.html
https://docs.splunk.com/Documentation/Splunk/6.6.2/Troubleshooting/Usebtooltotroubleshootconfigurati...
Pardon me .What exactly I meant to ask is We have list of hosts not reporting in splunk .I am looking for best search to find out in UI why they are not reporting .
I would start with this and see if they are even talking to the indexers at all.
index=_internal source=*splunkd.log host=(YOURHOST)
If this returns no results, there is no transmission. In that case, check the that the service is started, that the port is open. Then check the $splunkhome$/var/log/splunk/splunkd.log for clues.
If there is communication, chances are you don't have any apps in place in $splunkhome$/etc/apps.
Splunk is running, but hasn't been told what to do.
Thanks!jduke
Start with the links above. If you get hung up, add a comment here.