Count of Splunk Errors Per Host _internal ItsJohnLocke Vote Up +4 Vote Down -1You already voted! The following Splunk query will list the number of errors associated with each host over a given time range: index=_internal sourcetype="splunkd" log_level="ERROR" host!=splunk_server | stats count by host | sort - count Share This: Tagged: internalsplunkdUniversal Forwarder