Splunk Search

display count of hostnames in first day of week have last_seen>30 days

cipi23
New Member

for 08.07.19 count number of hostnames that have last_seen > 30 days
for 01.07.19 count number of hostnames that have last_seen > 30 days
for 24.06.19 count number of hostnames that have last_seen > 30 days
for 17.06.19 count number of hostnames that have last_seen > 30 days

the output will look like this
week1 count
week2 count
week3 count
week4 count

all this i need to do in one search please help

Tags (1)
0 Karma

woodcock
Esteemed Legend

Like this:

index=<You Should Always Specify index=> AND sourcetype=<And sourcetype= Too> AND (host= 08.07.19" OR host="01.07.19" OR host="24.06.19" OR host="17.06.19") earliest=-4w
| timechart useother=f usenull=f span=1w dc(last_seen) AS count BY host
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...