<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk search to get to a field values belongs to particular field in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-a-Splunk-search-to-get-to-a-field-value-that/m-p/625278#M107465</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;transaction command is usually very slow, and muste be used as last chance, please try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=indexname sourcetype=sourcetypename
| eval Actualstarttime=strftime(strptime(NEXT_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| eval Job_start_by=strftime(strptime(LAST_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| stats 
   values(JOB_NAME) AS JOB_NAME
   values(JOB_GROUP) AS JOB_GROUP
   values(REGION) AS REGION
   values(TIMEZONE) AS TIMEZONE
   values(STATUS) AS STATUS
   values(Currenttime) AS Currenttime
   values(STATUS_TIME) AS STATUS_TIME
   values(LAST_START) AS LAST_START
   values(LAST_END) AS LAST_END
   values(NEXT_START) AS NEXT_START
   values(DAYS_OF_WEEK) AS DAYS_OF_WEEK
   values(EXCLUDE_CALENDAR) AS EXCLUDE_CALENDAR
   values(RUNTIME) AS RUNTIME
   values(Actualstarttime) AS Actualstarttime
   values(Job_start_by) AS Job_start_by
   values(START_SLA) AS START_SLA
   values(AVG_RUN_TIME) AS AVG_RUN_TIME
   BY BOX_NAME&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 26 Dec 2022 16:31:35 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-12-26T16:31:35Z</dc:date>
    <item>
      <title>How to write a Splunk search to get to a field value that belongs to particular field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-a-Splunk-search-to-get-to-a-field-value-that/m-p/625256#M107462</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;
&lt;P&gt;i am using search query to correlate one field belongs and related jobs for that field&lt;/P&gt;
&lt;P&gt;i am using below query using transaction but i am trying to get unique value for one field but values are missing for other fields also.&lt;/P&gt;
&lt;P&gt;correct my query&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as my output expecting is in the table name of the BOX_NAME with one unque value and respective JOB_NAME under BOX_NAME&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=indexname sourcetype=sourcetypename
| eval Actualstarttime=strftime(strptime(NEXT_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| eval Job_start_by=strftime(strptime(LAST_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| transaction BOX_NAME
| table BOX_NAME,JOB_NAME,JOB_GROUP,REGION,TIMEZONE,STATUS,Currenttime,STATUS_TIME,LAST_START,LAST_END,NEXT_START,DAYS_OF_WEEK,EXCLUDE_CALENDAR,RUNTIME,Actualstarttime,Job_start_by,START_SLA,AVG_RUN_TIME

&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 29 Dec 2022 03:29:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-a-Splunk-search-to-get-to-a-field-value-that/m-p/625256#M107462</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2022-12-29T03:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search to get to a field values belongs to particular field</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-a-Splunk-search-to-get-to-a-field-value-that/m-p/625278#M107465</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;transaction command is usually very slow, and muste be used as last chance, please try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=indexname sourcetype=sourcetypename
| eval Actualstarttime=strftime(strptime(NEXT_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| eval Job_start_by=strftime(strptime(LAST_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| stats 
   values(JOB_NAME) AS JOB_NAME
   values(JOB_GROUP) AS JOB_GROUP
   values(REGION) AS REGION
   values(TIMEZONE) AS TIMEZONE
   values(STATUS) AS STATUS
   values(Currenttime) AS Currenttime
   values(STATUS_TIME) AS STATUS_TIME
   values(LAST_START) AS LAST_START
   values(LAST_END) AS LAST_END
   values(NEXT_START) AS NEXT_START
   values(DAYS_OF_WEEK) AS DAYS_OF_WEEK
   values(EXCLUDE_CALENDAR) AS EXCLUDE_CALENDAR
   values(RUNTIME) AS RUNTIME
   values(Actualstarttime) AS Actualstarttime
   values(Job_start_by) AS Job_start_by
   values(START_SLA) AS START_SLA
   values(AVG_RUN_TIME) AS AVG_RUN_TIME
   BY BOX_NAME&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 26 Dec 2022 16:31:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-a-Splunk-search-to-get-to-a-field-value-that/m-p/625278#M107465</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-26T16:31:35Z</dc:date>
    </item>
  </channel>
</rss>

