Splunk Search

How to search through the logs and display the result accordingly in eval

srinivas0704
New Member

I have to search for three statements in logs
1)CLI
2)ADM
3)GPO
How do I search for this and display which one of these is not present? And store the result,for ex:If CLI is not found display CLI

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Finding something that is not there is always a challenge. This blog post (https://www.duanewaddle.com/proving-a-negative/) addresses it well.

---
If this reply helps you, Karma would be appreciated.

srinivas0704
New Member

@richgalloway Thanks for looking into,I am OK with other approach as well of searching this. Mainly I have to search either three of these are found,if any one of them is found,initialise value to CLI,GPO or ADM

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...