How do we find total number of host or source type reporting splunk instance. Report should consider host across the cluster?
Answer / Manish Arora
To find the total number of hosts or source types reporting to a Splunk instance, you can use the `spath stats index=_internal/sourcetypes` command. This will give you a summary of all sourcetypes along with their count of events. To get this information across the cluster, you would need to run this command on each node and then aggregate the results.
| Is This Answer Correct ? | 0 Yes | 0 No |
Name the domain in which knowledge objects can be used?
What is the use of syslog server?
Where to download splunk cloud?
What are the unique benefits of getting data into a splunk instance via forwarders?
What is the use of a summary index?
How to reset splunk admin password?
State the difference between stats and event stats commands?
What is sos?
Explain types of search modes in splunk?
What is a lookup command?
How splunk works.
Explain Trouble shooting Splunk errors in splunk?