For more recent versions of Splunk (for example, version 7.3 in 2019), you can set proxy values in server.conf :
[proxyConfig]
http_proxy = http://proxy.example.com
https_proxy = https://proxy.example.com
See https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/ConfigureSplunkforproxy for details.
... View more
I know this is an old question, but to show details for each host, use limit=0 , for example:
| timechart span=1d count by host limit 0
See Timechart for details.
... View more