Splunk Search

can i get the one particular host information from the metadata command?

pentela114
Engager

I am using the below command and it is giving me the whole host lists in the environment, but i need for the particular host. Please suggest?

| metadata type=hosts index=*

Tags (1)

somesoni2
Revered Legend

The metadata command has only index and splunk_server (indexers/search peers) filter, so either you can filter your host information like this

| metadata type=hosts index=* | where host="YourHostHere"

OR use this to get data for just your host.

| tstats count as totalCount min(_time) as firstTime max(_time) as lastTime max(_time) as recentTime WHERE index=* host="YourHostHere"  by host
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...