<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic search help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/search-help/m-p/559442#M158935</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am looking for a little help with a search today. I am looking to create an alert based on this search that only triggers when the same hostname comes up twice in a row.&amp;nbsp;&lt;/P&gt;&lt;P&gt;so far the search I have is I am unsure how to include/return two machines of the same name:&lt;/P&gt;&lt;P&gt;index="login_pi" source="WinEventLog:LoginPI Events" SourceName="Application Threshold Exceeded"&lt;BR /&gt;| rex field=_raw "Actual value\\\":\s+\\\"(?&amp;lt;actual_value&amp;gt;\d+)"&lt;BR /&gt;| search actual_value&amp;gt;=10&lt;BR /&gt;| table Target,actual_value,ApplicationName,Title&lt;/P&gt;&lt;P&gt;here is an example event:&lt;/P&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;07/14/2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10:39:49&lt;/SPAN&gt; &lt;SPAN class="t"&gt;AM&lt;/SPAN&gt; &lt;SPAN class="t"&gt;LogName=LoginPI&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Events&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EventCode=800&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EventType=4&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ComputerName=RNBSVSIMGT02.rightnetworks.com&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SourceName=Application&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Exceeded&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Type=Information&lt;/SPAN&gt; &lt;SPAN class="t"&gt;RecordNumber=1786721&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Keywords=Classic&lt;/SPAN&gt; &lt;SPAN class="t"&gt;TaskCategory=None&lt;/SPAN&gt; &lt;SPAN class="t"&gt;OpCode=Info&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Message=&lt;/SPAN&gt;{ "&lt;SPAN class="t"&gt;Description&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;Measurement&lt;/SPAN&gt; &lt;SPAN class="t"&gt;duration&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;7.561s&lt;/SPAN&gt;) &lt;SPAN class="t"&gt;exceeded&lt;/SPAN&gt; &lt;SPAN class="t"&gt;threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;of&lt;/SPAN&gt; &lt;SPAN class="t"&gt;5s&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;51.22%&lt;/SPAN&gt;)", "&lt;SPAN class="t"&gt;Actual&lt;/SPAN&gt; &lt;SPAN class="t"&gt;value&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;7.561&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;value&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;5&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Measurement&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;quickbooksopen_2021&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Locale&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;English&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;United&lt;/SPAN&gt; &lt;SPAN class="t"&gt;States&lt;/SPAN&gt;)", "&lt;SPAN class="t"&gt;RemotingProtocol&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;Rdp&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Resolution&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;1920&lt;/SPAN&gt; &lt;SPAN class="t"&gt;×&lt;/SPAN&gt; &lt;SPAN class="t"&gt;1080&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;ScaleFactor&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;100%&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Target&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;BPOQCP01S01&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;TargetOS&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t h"&gt;Microsoft&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Windows&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Server&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2016&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Standard&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.0.14393&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;1607&lt;/SPAN&gt;)", "&lt;SPAN class="t"&gt;AppExecutionId&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;4ed43186-648c-4e8e-96ee-9e4b52e468cb&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;AccountId&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;a4a6655b-f7ac-4783-aec5-698a146eb2cf&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;AccountName&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;rightnetworks\\eloginpi082&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;LauncherName&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;RNBSVSI23&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;EnvironmentName&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;BPOQCP01S01&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;EnvironmentId&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;bc31c8f6-e8c0-4278-93c3-08d8040960f8&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;ApplicationName&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;QB_2021_Open&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;ApplicationId&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;ece9c6b9-6662-45be-970d-2708603ca13b&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Title&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;Application&lt;/SPAN&gt; &lt;SPAN class="t"&gt;threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;exceeded&lt;/SPAN&gt;" }&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 14 Jul 2021 15:01:56 GMT</pubDate>
    <dc:creator>tkerr1357</dc:creator>
    <dc:date>2021-07-14T15:01:56Z</dc:date>
    <item>
      <title>search help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-help/m-p/559442#M158935</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am looking for a little help with a search today. I am looking to create an alert based on this search that only triggers when the same hostname comes up twice in a row.&amp;nbsp;&lt;/P&gt;&lt;P&gt;so far the search I have is I am unsure how to include/return two machines of the same name:&lt;/P&gt;&lt;P&gt;index="login_pi" source="WinEventLog:LoginPI Events" SourceName="Application Threshold Exceeded"&lt;BR /&gt;| rex field=_raw "Actual value\\\":\s+\\\"(?&amp;lt;actual_value&amp;gt;\d+)"&lt;BR /&gt;| search actual_value&amp;gt;=10&lt;BR /&gt;| table Target,actual_value,ApplicationName,Title&lt;/P&gt;&lt;P&gt;here is an example event:&lt;/P&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;07/14/2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10:39:49&lt;/SPAN&gt; &lt;SPAN class="t"&gt;AM&lt;/SPAN&gt; &lt;SPAN class="t"&gt;LogName=LoginPI&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Events&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EventCode=800&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EventType=4&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ComputerName=RNBSVSIMGT02.rightnetworks.com&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SourceName=Application&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Exceeded&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Type=Information&lt;/SPAN&gt; &lt;SPAN class="t"&gt;RecordNumber=1786721&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Keywords=Classic&lt;/SPAN&gt; &lt;SPAN class="t"&gt;TaskCategory=None&lt;/SPAN&gt; &lt;SPAN class="t"&gt;OpCode=Info&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Message=&lt;/SPAN&gt;{ "&lt;SPAN class="t"&gt;Description&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;Measurement&lt;/SPAN&gt; &lt;SPAN class="t"&gt;duration&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;7.561s&lt;/SPAN&gt;) &lt;SPAN class="t"&gt;exceeded&lt;/SPAN&gt; &lt;SPAN class="t"&gt;threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;of&lt;/SPAN&gt; &lt;SPAN class="t"&gt;5s&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;51.22%&lt;/SPAN&gt;)", "&lt;SPAN class="t"&gt;Actual&lt;/SPAN&gt; &lt;SPAN class="t"&gt;value&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;7.561&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;value&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;5&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Measurement&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;quickbooksopen_2021&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Locale&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;English&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;United&lt;/SPAN&gt; &lt;SPAN class="t"&gt;States&lt;/SPAN&gt;)", "&lt;SPAN class="t"&gt;RemotingProtocol&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;Rdp&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Resolution&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;1920&lt;/SPAN&gt; &lt;SPAN class="t"&gt;×&lt;/SPAN&gt; &lt;SPAN class="t"&gt;1080&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;ScaleFactor&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;100%&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Target&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;BPOQCP01S01&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;TargetOS&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t h"&gt;Microsoft&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Windows&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Server&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2016&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Standard&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.0.14393&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;1607&lt;/SPAN&gt;)", "&lt;SPAN class="t"&gt;AppExecutionId&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;4ed43186-648c-4e8e-96ee-9e4b52e468cb&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;AccountId&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;a4a6655b-f7ac-4783-aec5-698a146eb2cf&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;AccountName&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;rightnetworks\\eloginpi082&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;LauncherName&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;RNBSVSI23&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;EnvironmentName&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;BPOQCP01S01&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;EnvironmentId&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;bc31c8f6-e8c0-4278-93c3-08d8040960f8&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;ApplicationName&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;QB_2021_Open&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;ApplicationId&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;ece9c6b9-6662-45be-970d-2708603ca13b&lt;/SPAN&gt;", "&lt;SPAN class="t"&gt;Title&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;Application&lt;/SPAN&gt; &lt;SPAN class="t"&gt;threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;exceeded&lt;/SPAN&gt;" }&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 Jul 2021 15:01:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-help/m-p/559442#M158935</guid>
      <dc:creator>tkerr1357</dc:creator>
      <dc:date>2021-07-14T15:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: search help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-help/m-p/559457#M158938</link>
      <description>&lt;LI-CODE lang="markup"&gt;| streamstats values(ComputerName) as ComputerNameValues list(ComputerName) as ComputerNameList window=2
| where mvcount(ComputerNameValues) = 1 AND mvcount(ComputerNameList) = 2&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 14 Jul 2021 16:05:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-help/m-p/559457#M158938</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-14T16:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: search help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-help/m-p/559470#M158940</link>
      <description>&lt;P&gt;I changed it to target instead of computername but this did the trick.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 17:00:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-help/m-p/559470#M158940</guid>
      <dc:creator>tkerr1357</dc:creator>
      <dc:date>2021-07-14T17:00:59Z</dc:date>
    </item>
  </channel>
</rss>

