Splunk Search

when the machine was build or when the machine started communicating to Splunk

brpsingara
Explorer

I got regular question from auditors.
we have 100 machines,
Machine1
Machine2
..
..
Machine100

and auditor asked to run/search one year old data for the 'machine34'.
I did search by using * host=machine34 and manually i selected 2019 March
If data is there i am fine, but unfortunately data is not showing. Because the machine34 was build 2 months back. It took 2 hours to find the solutions for this. So...,

My question is possible to see build date or 1st contact date of machine by using splunk.

I am using below code to view the all machines

| metadata type=hosts index=* | stats count by host

I am looking for another field, that is build date or contacting to splunk date.

Will it be possible ?

Thanks in advance.

Labels (1)
Tags (1)
0 Karma
1 Solution

lloydknight
Builder

Hi @brpsingara

| metadata type=hosts index=_internal 
| rename totalCount as Count firstTime as "First Event" lastTime as "Last Event" recentTime as "Last Update" 
| fieldformat Count=tostring(Count, "commas") 
| fieldformat "First Event"=strftime('First Event', "%c") 
| fieldformat "Last Event"=strftime('Last Event', "%c") 
| fieldformat "Last Update"=strftime('Last Update', "%c")

This sample search is basically just taken on the official docs Search Reference.
https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchReference/Metadata

Hope it helps!

View solution in original post

0 Karma

lloydknight
Builder

Hi @brpsingara

| metadata type=hosts index=_internal 
| rename totalCount as Count firstTime as "First Event" lastTime as "Last Event" recentTime as "Last Update" 
| fieldformat Count=tostring(Count, "commas") 
| fieldformat "First Event"=strftime('First Event', "%c") 
| fieldformat "Last Event"=strftime('Last Event', "%c") 
| fieldformat "Last Update"=strftime('Last Update', "%c")

This sample search is basically just taken on the official docs Search Reference.
https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchReference/Metadata

Hope it helps!

0 Karma

brpsingara
Explorer

Thanks lloydknight

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...