I would run
| metadata index="foo" type=hosts | outputcsv foo_hosts
for each index that could contain host indexed data.
I would run
| metadata index="foo" type=hosts | outputcsv foo_hosts
for each index that could contain host indexed data.
Thanks.. i figured that one out while you were posting. Splunk Answers--from the keyboard directly to my mind.