Splunk search for Hosts forwarding internal logs to Indexers

Copy
index=_internal sourcetype=splunkd | stats dc(hostname) as "Unique Splunk Hosts"
This search will provide a count of the number of unique hosts that are forwarding their internal logs to Splunk. In practice this will be any instances that have an outputs.conf pointing to the indexer layer.
0 comments

Category:

General Splunk


Tags:

administration internal

Search Commands:

Sign in or Register to submit a comment