question

sanketasosatti-5722 avatar image
0 Votes"
sanketasosatti-5722 asked IanXue-MSFT answered

Splunk query to identify the list of printers from a host=print server, which are not printed for years

Team,
i have been using splunk as a monitoring tool for all our infra printers, i am unable to identify the unused\neverprinted printers to clean up.

this query is just giving me the list of printers printed events, but not the unused printers from long years.

host=USSLCPRTHPENG0* SourceName=Print | rex "printed on (?<Printer_queue>\w+)" |rex "port (?<Port>\w+)" |rex "Size in bytes: (?<Size>\w+)" | search Printer_queue = * | timechart count(_raw) by Printer_queue limit=150


host="usslcp1prapac01" SourceName=Print | rex "printed on (?<Printer_queue>\w+)" |rex "port (?<Port>\w+)" |rex "Size in bytes: (?<Size>\w+)" | search Printer_queue = * | timechart count(_raw) by Printer_queue

windows-server-powershell
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

IanXue-MSFT avatar image
0 Votes"
IanXue-MSFT answered

Hi @sanketasosatti-5722

As your issue is related to the Splunk Search Processing Language rather than PowerShell, you'd better ask the question in the splunk community

https://community.splunk.com/t5/Community/ct-p/en-us

Best Regards,
Ian Xue
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.