Alerting

Need help to generate report based in table format

syedak
New Member

Need help to generate report based in table format in below format.

Hostname OS IPaddress LastLogReceived

SRV1 Win 10.x.x.x 25/01/2018
SRV2 Win 10.x.x.x 25/01/2018

SRV3 Linux 10.x.x.x 25/01/2018

TotalSRV = 3

Tags (2)
0 Karma
1 Solution

mayurr98
Super Champion

hey, could you provide some sample events?

If all of the columns are already extracted then with the columns provided then you can try something like this

index=<your_index> | table Hostname OS IPaddress LastLogReceived

let me know if this helps!

View solution in original post

0 Karma

mayurr98
Super Champion

hey, could you provide some sample events?

If all of the columns are already extracted then with the columns provided then you can try something like this

index=<your_index> | table Hostname OS IPaddress LastLogReceived

let me know if this helps!

0 Karma

syedak
New Member

Hi Mayurr98,
Thanks for the help.

I need something like this in my report

|Srv1 | 10.x.x.x| Windows|

|Srv2 | 10.x.x.x| Windows|
|Srv3 | 10.x.x.x| Windows|
|Tot Srv = 3(count of servers)|

Below is my search which i used for daily report, on top of this query i also need to count number of hostname that are present in this search result.

index= _internal fwdType ="*"
|eval lastUpdate=strftime(_time, "%d - %m -%Y %H:%M:%S")
|dedup hostname
| sort hostname asc
| table hostname, os, sourceHost, lastupdate
0 Karma

mayurr98
Super Champion

Try this :

index=_internal fwdType="*" 
| eval lastUpdate=strftime(_time,"%d-%m-%Y %H:%M:%S") 
| dedup hostname 
| stats dc(hostname) as dc_count by hostname, os, sourceHost, lastUpdate 
| sort hostname asc 
| addcoltotals dc_count labelfield=hostname label="Total SRV"
0 Karma

syedak
New Member

Thanks Mayurr98.
Worked for me to certain level.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...