Hi,
When I run the searches below separately, they give me exact result, but when I tried joining them, it was not successful. Is there any way of joining them efficiently? Below are the searches and condition host=hostname
.
| metadata type=hosts| sort -recentTime| convert ctime(recentTime) as Last_Report_Time
index=_internal fwdType="*"|dedup sourceHost| table sourceHost, hostname, os
Hi Sampathu,
what's your intension to do so - do you want to find forwarder not sending and create an alert?
If so don't re-invent the wheel - either use this app https://splunkbase.splunk.com/app/1294/#/overview if your pre Splunk 6.2 or run DMC http://docs.splunk.com/Documentation/Splunk/6.3.0/DMC/DMCoverview
Both have plenty of pre-build alerts to handle this.
Hope this helps ...
cheers, MuS