Looking to see how I would export a list of all hosts which have reported to splunk all time. I can generate the info with * | top hosts limit 10000, however it takes forever to complete... there has to be a faster search as I am not concerned with the total events per host, just looking for a list of hosts.
You should be able to see the lists of hosts with the metadata command:
| metadata type=hosts index=*
You can get a nice ordered list with this:
| metadata type=hosts index=* | stats count by host
You should be able to see the lists of hosts with the metadata command:
| metadata type=hosts index=*