Count of Splunk Errors Per Host

The following Splunk query will list the number of errors associated with each host over a given time range:

index=_internal sourcetype="splunkd" log_level="ERROR"  host!=splunk_server | stats count by host | sort - count
Share This:

Leave A Comment?