List All Hosts Associated with All Indexes _internal SplunkNinja 1 Comment Vote Up +21 Vote Down -2You already voted! Using the Splunk Tstats command you can quickly list all hosts associated with all indexes: |tstats values(host) where index=* by index Share This: Tagged: Diagnosticsinternaltroubleshootingtstats
Not sure WHY this is, but using the group keyword here chomps results for us. In some cases we are missing hosts. Re-writing the query without it like this:
|tstats values(host) where index=* by index
gives us more accurate results.