Splunk Search

Field mapping from number to names

michael_lee
Path Finder

Say for instance I am searching for windows event codes and types and I have a list of the event code mapping to their text description. How can I show in my search output the Event code mapped to their names? thanks

Tags (1)
0 Karma

fdi01
Motivator

try like :

your_base_search|stats list("fields name Event code") as " Event code" by "fields name of  text description" |....
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...