Splunk Search

How to search for all devices in my environment that are sending logs to Splunk?

AaronMoorcroft
Communicator

Morning Guys

I'm mid plan for ripping out our Splunk environment and starting again. As some of you may be aware from my past questions, I inherited our current Splunk environment which I don't believe was in a great state.

I'm looking at effectively starting fresh, but I don't know of all the devices sending in logs. Is there a search I can run that will pick up everything, Servers, Network Devices, everything else?

I have multiple Heavy Forwarders sending on logs from all over the place, all going to one indexer with a mini Splunk environment bolted on to that too. If someone could advise that would be awesome.

Thanks as always

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

You can run thorough all of the metadata.

|metadata type=hosts index=*

This will pull the metadata host value for anything on your indexer. This would be a quick starting point for you.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

You can run thorough all of the metadata.

|metadata type=hosts index=*

This will pull the metadata host value for anything on your indexer. This would be a quick starting point for you.

AaronMoorcroft
Communicator

Thank you 🙂

0 Karma

brewster88
New Member

Extremely useful answer, life saver today!

0 Karma
Get Updates on the Splunk Community!

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...