Splunk Search

Grouping field values which are in common

Motivator

My incoming logs has several hosts and many services running in each hosts.

I would like to generate a table from my logs in the below format.

HOST SERVICE
host1 chrome
      http
      taskmgr
host2 chrome
host3 http
      chrome
host4 servicex

What is the splunk command i can use ? Is there any per-defiened command for this fucntion

Tags (3)
0 Karma
1 Solution

Motivator

How about something like this:

... your base search ... | stats values(SERVICE) AS SERVICE by HOST

View solution in original post

Motivator

How about something like this:

... your base search ... | stats values(SERVICE) AS SERVICE by HOST

View solution in original post

Motivator

thanks....

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!