Splunk Search

can i get the one particular host information from the metadata command?

pentela114
Engager

I am using the below command and it is giving me the whole host lists in the environment, but i need for the particular host. Please suggest?

| metadata type=hosts index=*

Tags (1)

somesoni2
Revered Legend

The metadata command has only index and splunk_server (indexers/search peers) filter, so either you can filter your host information like this

| metadata type=hosts index=* | where host="YourHostHere"

OR use this to get data for just your host.

| tstats count as totalCount min(_time) as firstTime max(_time) as lastTime max(_time) as recentTime WHERE index=* host="YourHostHere"  by host
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...