Splunk Search

How can I display values of a common field occurring in two different event ID's?

ASTARS47
New Member

There are various event codes like eventID = "123" , eventID ="456", eventID = "789" . There are some "appID"   fields that occurs in both eventID = "123"  AND eventID ="456"  (not all "appID" occur in both these eventID) . So I want to display a list of values from all those "appID"  field which are occurring in both the eventID = "123"  AND eventID ="456" 

Please let me know how can I achieve it. I also have a large data set here.

Thank you.

Labels (5)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

| eventstats values(eventID) as eventids by appID
| where match(eventids, "123") AND match(eventids,"456")
0 Karma
Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...