Splunk Search

display count of hostnames in first day of week have last_seen>30 days

cipi23
New Member

for 08.07.19 count number of hostnames that have last_seen > 30 days
for 01.07.19 count number of hostnames that have last_seen > 30 days
for 24.06.19 count number of hostnames that have last_seen > 30 days
for 17.06.19 count number of hostnames that have last_seen > 30 days

the output will look like this
week1 count
week2 count
week3 count
week4 count

all this i need to do in one search please help

Tags (1)
0 Karma

woodcock
Esteemed Legend

Like this:

index=<You Should Always Specify index=> AND sourcetype=<And sourcetype= Too> AND (host= 08.07.19" OR host="01.07.19" OR host="24.06.19" OR host="17.06.19") earliest=-4w
| timechart useother=f usenull=f span=1w dc(last_seen) AS count BY host
0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...